Vulnerability record · CVE-2012-1424 · published 21 March 2012
CVE-2012-1424: Antivirus TAR parser malware detection bypass via crafted POSIX TAR
Antiy · Avl Sdk
The TAR file parser in multiple antivirus products (Antiy AVL SDK, Quick Heal, Jiangmin, Norman, PC Tools, Sophos) fails to correctly handle a POSIX TAR file containing a specific \19\04\00\10 character sequence, allowing malware detection to be bypassed. Because the flaw affects the scanning engine itself, a malicious archive can pass through the antivirus undetected, undermining the core protection these products provide. The record notes it may later be split into separate CVEs if the error is shown to occur independently across the different TAR parser implementations.
Description
The TAR file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Jiangmin Antivirus 13.0.900, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityCVSS 2.0 base score is 4.3 (MEDIUM) with integrity-only impact, but the flaw defeats malware detection across several widely used antivirus products and EPSS is very high.
What it is
The TAR file parser in multiple antivirus products (Antiy AVL SDK, Quick Heal, Jiangmin, Norman, PC Tools, Sophos) fails to correctly handle a POSIX TAR file containing a specific \19\04\00\10 character sequence, allowing malware detection to be bypassed. Because the flaw affects the scanning engine itself, a malicious archive can pass through the antivirus undetected, undermining the core protection these products provide. The record notes it may later be split into separate CVEs if the error is shown to occur independently across the different TAR parser implementations.
Impact
An attacker can deliver a malicious TAR archive that evades detection by the affected antivirus products, allowing malware to reach the target system without being flagged. The direct gain is detection bypass rather than code execution or data access on the scanner itself.
Attack surface
The flaw is reached remotely over the network (AV:N) by supplying a crafted POSIX TAR file to the affected scanning engine; no authentication is required (Au:N). Some user interaction is implied by the AC:M vector, consistent with a victim opening or scanning the malicious archive.
Exploitation
Not listed in CISA KEV and no reference tags indicate public exploit code, but EPSS is very high (0.87288, 99.7th percentile), suggesting elevated predicted exploitation activity. The record does not confirm in-the-wild exploitation.
What to do
- Apply vendor updates for the affected antivirus products; the record does not list fixed versions, so confirm patch availability with each vendor (Antiy, Quick Heal, Jiangmin, Norman, PC Tools, Sophos).
- Where patching is unavailable, supplement the affected scanner with a second, independently maintained detection engine for TAR archives.
- Block or quarantine inbound TAR archives at email and web gateways until scanners are confirmed patched.
- Restrict user handling of untrusted archives and enforce attachment filtering policies.
- Track the NVD record for a possible CVE split, which may change which products and fixes apply.
Detection
- Monitor for TAR archives containing the \19\04\00\10 byte sequence at the described location in file submission and gateway logs.
- Correlate endpoint and gateway scan results for archives that pass one engine but are flagged by another.
- Alert on TAR files delivered from external sources that trigger no detection across the affected product set.
- Review historical quarantine and scan logs for TAR files that were allowed through during the exposure window.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1424 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1424), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.