Vulnerability record · CVE-2012-1427 · published 21 March 2012
CVE-2012-1427: Quick Heal, Norman, Sophos TAR parser malware detection bypass
Cat · Quick Heal
The TAR file parser in Quick Heal 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 can be tricked by a POSIX TAR file containing a specific character sequence (\57\69\6E\5A\69\70) at a certain location. This lets a crafted archive evade malware detection, so malicious content inside the TAR may reach the user or system without being flagged. The record notes it may later be split into multiple CVEs if the flaw is shown to occur independently in different TAR parser implementations.
Description
The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \57\69\6E\5A\69\70 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityCVSS 2.0 is 4.3 (MEDIUM) and impact is limited to detection bypass, but the high EPSS score and antivirus-evasion nature warrant attention.
What it is
The TAR file parser in Quick Heal 11.00, Norman Antivirus 6.06.12, and Sophos Anti-Virus 4.61.0 can be tricked by a POSIX TAR file containing a specific character sequence (\57\69\6E\5A\69\70) at a certain location. This lets a crafted archive evade malware detection, so malicious content inside the TAR may reach the user or system without being flagged. The record notes it may later be split into multiple CVEs if the flaw is shown to occur independently in different TAR parser implementations.
Impact
An attacker can bypass the antivirus TAR scanning and deliver malware that the product would otherwise detect. The direct gain is evasion of detection, not code execution or data access on its own.
Attack surface
Reached remotely by supplying a crafted POSIX TAR file to the affected antivirus parser, typically as a file the victim or a scanning pipeline processes. No authentication is required per the CVSS vector (AV:N/AC:M/Au:N), but some user interaction or automated file handling is needed to get the archive scanned.
Exploitation
Not listed in CISA KEV and no reference tags indicate public exploit code. EPSS is high (0.876, 99.7th percentile), suggesting elevated predicted exploitation activity, but the record does not confirm active exploitation.
What to do
- Apply vendor updates for Quick Heal, Norman Antivirus, and Sophos Anti-Virus; if no fix is available, confirm current status with each vendor.
- Do not rely on TAR scanning alone; add independent file inspection or sandboxing for archives before they reach endpoints.
- Block or quarantine untrusted TAR archives at email and web gateways where feasible.
- Re-scan or re-evaluate previously scanned TAR files with updated signatures and parsers after patching.
Detection
- Monitor for TAR files containing the byte sequence 57 69 6E 5A 69 70 at the location described in the advisory.
- Alert on antivirus scan results that show TAR archives passing without expected detection, especially from external sources.
- Hunt for repeated delivery of TAR archives to endpoints running the affected product versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1427 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1427), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.