CVE-2012-1456

CVSS 4.3 - MEDIUM
Description

The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

Affected Products
20
Vendor Product Version
aladdin esafe 7.0.17.0
avg avg_anti-virus 10.0.0.1190
cat quick_heal 11.00
comodo comodo_antivirus 7424
emsisoft anti-malware 5.1.0.1
eset nod32_antivirus 5795
f-prot f-prot_antivirus 4.6.2.117
fortinet fortinet_antivirus 4.2.254.0
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
jiangmin jiangmin_antivirus 13.0.900
kaspersky kaspersky_anti-virus 7.0.0.125
mcafee gateway 2010.1c
mcafee scan_engine 5.400.0.1158
norman norman_antivirus_\&_antispyware 6.06.12
pandasecurity panda_antivirus 10.0.2.7
rising-global rising_antivirus 22.83.00.03
sophos sophos_anti-virus 4.61.0
symantec endpoint_protection 11.0
trendmicro housecall 9.120.0.1004
trendmicro trend_micro_antivirus 9.120.0.1004
Weakness Types
CWE-264
CVE Information
CVE ID:
CVE-2012-1456
Published:
2012-03-21
Modified:
2026-04-29
CVSS Score:
4.3
Severity:
MEDIUM
Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N
Affected Vendors
norman rising-global pandasecurity f-prot trendmicro avg kaspersky jiangmin eset aladdin mcafee symantec emsisoft cat sophos comodo fortinet ikarus
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL