cbcvebase.
CVE-2012-1457
published 2012-03-21

CVE-2012-1457: The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender…

PriorityP344medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
98.29%
99.9th percentile
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
aladdinesafe
alwilavast_antivirus
alwilavast_antivirus
anti-virusvba32
antiyavl_sdk
authentiumcommand_antivirus
avgavg_anti-virus
aviraantivir
bitdefenderbitdefender
catquick_heal
clamavclamav
clamavclamav>= 0 < 0.97.5+dfsg-10.97.5+dfsg-1
clamavclamav>= 0 < 0.97.5+dfsg-10.97.5+dfsg-1
clamavclamav>= 0 < 0.97.5+dfsg-10.97.5+dfsg-1
clamavclamav>= 0 < 0.97.5+dfsg-10.97.5+dfsg-1
debianclamav< clamav 0.97.5+dfsg-1 (bookworm)clamav 0.97.5+dfsg-1 (bookworm)
emsisoftanti-malware
esetnod32_antivirus
f-protf-prot_antivirus
gdata-softwareg_data_antivirus
ikarusikarus_virus_utilities_t3_command_line_scanner
jiangminjiangmin_antivirus
k7computingantivirus
kasperskykaspersky_anti-virus
mcafeegateway

Detection & IOCsextracted from sources · hover to see the quote

commandTAR archive entry with a length field that exceeds the total TAR file size
  • Detect TAR archives where any entry's length field value exceeds the total size of the TAR file — this is the evasion trigger for CVE-2012-1457 across all affected AV parsers.
  • ClamAV specifically was confirmed vulnerable at version 0.96.4; the fix was introduced in ClamAV 0.97.5. Scan engines running versions below 0.97.5 should be flagged.
  • A remote attacker can craft a TAR file containing malware that evades detection; inspect TAR files at the network perimeter for oversized entry length fields relative to the total archive size.
  • The evasion technique was publicly disclosed via a BugTraq post titled 'Evasion attacks exploiting file-parsing vulnerabilities in antivirus products' on 2012-03-19; correlate IDS/proxy logs around that date for TAR file delivery.
  • ·The vulnerability may be split into multiple CVEs in the future if it is determined that each affected AV vendor's TAR parser failed independently; detections should account for all listed affected products.
  • ·The ClamAV fix (0.97.5) initially introduced a regression that could cause it to fail to scan certain documents; verify the regression fix (USN-1482-3) is also applied.
  • ·For Debian-based systems, the fix is present in ClamAV package version 0.97.5+dfsg-1 across all tracked suites (bookworm, bullseye, sid, trixie, forky).

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.