CVE-2012-1425

N/A Unknown
Published: March 21, 2012 Modified: April 29, 2026
View on NVD

Description

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \50\4B\03\04 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/80389
Source: cve@mitre.org
http://osvdb.org/80391
Source: cve@mitre.org
http://osvdb.org/80392
Source: cve@mitre.org
http://osvdb.org/80395
Source: cve@mitre.org
http://osvdb.org/80396
Source: cve@mitre.org
http://osvdb.org/80403
Source: cve@mitre.org
http://osvdb.org/80409
Source: cve@mitre.org
http://osvdb.org/80389
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80391
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80392
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80395
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80396
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80403
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/80409
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ieee-security.org/TC/SP2012/program.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/522005
Source: af854a3a-2127-422b-91ae-364da2661108

18 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
93.3%
100th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

cat ikarus symantec fortinet mcafee norman pc_tools antiy eset avira +4 more