cbcvebase.
CVE-2012-1420
published 2012-03-21

CVE-2012-1420: The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus…

medium4.3CVSS 3.1
AVNACMAuNCNIPAN
The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

Affected

11 ranges
VendorProductVersion rangeFixed in
authentiumcommand_antivirus
catquick_heal
esetnod32_antivirus
f-protf-prot_antivirus
fortinetfortinet_antivirus
k7computingantivirus
kasperskykaspersky_anti-virus
microsoftsecurity_essentials
normannorman_antivirus_antispyware
pandasecuritypanda_antivirus
rising-globalrising_antivirus