Vulnerability CVE-2012-1457

Published: 2012-03-21

The TAR file parser in Avira AntiVir, Antiy Labs AVL SDK, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus, Emsisoft Anti-Malware, eSafe, F-Prot Antivirus, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus, Rising Antivirus, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus, Trend Micro HouseCall, VBA32, and VirusBuster allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.



(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
Exploit range
Attack complexity
No required
Confidentiality impact
Integrity impact
Availability impact
Affected software
Virusbuster -> Virusbuster 
Trendmicro -> Housecall 
Trendmicro -> Trend micro antivirus 
Symantec -> Endpoint protection 
Rising-global -> Rising antivirus 
Pc tools -> Pc tools antivirus 
Norman -> Norman antivirus & antispyware 
Microsoft -> Security essentials 
Mcafee -> Gateway 
Mcafee -> Scan engine 
Kaspersky -> Kaspersky anti-virus 
K7computing -> Antivirus 
Jiangmin -> Jiangmin antivirus 
Ikarus -> Ikarus virus utilities t3 command line scanner 
Gdata-software -> G data antivirus 
F-prot -> F-prot antivirus 
ESET -> Nod32 antivirus 
Emsisoft -> Anti-malware 
Clamav -> Clamav 
CAT -> Quick heal 
Bitdefender -> Bitdefender 
Avira -> Antivir 
AVG -> Avg anti-virus 
Authentium -> Command antivirus 
Antiy -> Avl sdk 
Anti-virus -> Vba32 
Alwil -> Avast antivirus 
Aladdin -> Esafe 


Copyright 2024,


Back to Top