4.3
CVSSv2

CVE-2012-1456

Published: 21/03/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote malicious users to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

aladdin esafe 7.0.17.0

f-prot f-prot antivirus 4.6.2.117

norman norman antivirus \\& antispyware 6.06.12

pandasecurity panda antivirus 10.0.2.7

comodo comodo antivirus 7424

emsisoft anti-malware 5.1.0.1

mcafee scan engine 5.400.0.1158

mcafee gateway 2010.1c

eset nod32 antivirus 5795

trendmicro trend micro antivirus 9.120.0.1004

fortinet fortinet antivirus 4.2.254.0

ikarus ikarus virus utilities t3 command line scanner 1.1.97.0

rising-global rising antivirus 22.83.00.03

sophos sophos anti-virus 4.61.0

avg avg anti-virus 10.0.0.1190

cat quick heal 11.00

jiangmin jiangmin antivirus 13.0.900

kaspersky kaspersky anti-virus 7.0.0.125

symantec endpoint protection 11.0

trendmicro housecall 9.120.0.1004