CVE-2012-1420

N/A Unknown
Published: March 21, 2012 Modified: April 29, 2026
View on NVD

Description

The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/80403
Source: cve@mitre.org
http://osvdb.org/80406
Source: cve@mitre.org
http://osvdb.org/80407
Source: cve@mitre.org
http://osvdb.org/80409
Source: cve@mitre.org
http://osvdb.org/80403
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80406
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80407
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80409
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ieee-security.org/TC/SP2012/program.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/522005
Source: af854a3a-2127-422b-91ae-364da2661108

12 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
97.1%
100th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

authentium cat microsoft f-prot k7computing fortinet norman pandasecurity eset rising-global +1 more