CVE-2012-1446: Aladdin Esafe

Medium severity, CVSS 4.3. EPSS: 99.7% chance of exploitation in the next 30 days.

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (formerly Webwasher) 2010.1C, Sophos Anti-Virus 4.61.0, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified encoding field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

Affected products

  • Aladdin Esafe: version 7.0.17.0 only
  • Antiy Avl SDK: version 2.0.3.7 only
  • Ca Etrust Vet Antivirus: version 36.1.8511 only
  • Cat Quick Heal: version 11.00 only
  • Fortinet Fortinet Antivirus: version 4.2.254.0 only
  • Kaspersky Kaspersky Anti-Virus: version 7.0.0.125 only
  • McAfee Gateway: version 2010.1c only
  • McAfee Scan Engine: version 5.400.0.1158 only
  • Norman Norman Antivirus & Antispyware: version 6.06.12 only
  • Pandasecurity Panda Antivirus: version 10.0.2.7 only
  • Pc Tools Pc Tools Antivirus: version 7.0.3.5 only
  • Rising-Global Rising Antivirus: version 22.83.00.03 only
  • Sophos Sophos Anti-Virus: version 4.61.0 only
  • Symantec Endpoint Protection: version 11.0 only

Published 2012-03-21. Last modified 2026-06-16.