← Vulnerability feed

Vulnerability record · CVE-2012-1459 · published 21 March 2012

CVE-2012-1459: TAR parser malware detection bypass in multiple antivirus products

Ahnlab · V3 Internet Security

The TAR file parser in dozens of antivirus products mishandles a TAR archive entry whose length field spans the entire entry plus part of the next entry's header. This lets a crafted archive evade malware detection, so malicious content passes through scanning undetected. The record covers many independent vendor implementations and may later be split into separate CVEs.

4.3 CVSS 2.0 Medium EPSS 100% · top 0.1% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
100%EPSS exploitation probability, 30 days
NoNot in CISA KEV
34Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

medium priorityCVSS 2.0 is 4.3 (MEDIUM) and the flaw only bypasses detection rather than executing code, but it affects a very broad set of security products and EPSS is extremely high.

What it is

The TAR file parser in dozens of antivirus products mishandles a TAR archive entry whose length field spans the entire entry plus part of the next entry's header. This lets a crafted archive evade malware detection, so malicious content passes through scanning undetected. The record covers many independent vendor implementations and may later be split into separate CVEs.

Impact

An attacker can deliver malware inside a crafted TAR archive that the affected scanner fails to flag, defeating the primary detection control. No code execution or data modification on the scanner host is described; the gain is evasion of malware detection.

Attack surface

Reached remotely by supplying a malicious TAR archive to a scanning interface, as reflected by the AV:N network vector. No authentication is required (Au:N), but exploitation depends on the target processing the crafted archive, which the AC:M vector indicates is not fully reliable.

Exploitation

Not listed in CISA KEV and no reference is tagged as exploit code, though EPSS is very high (0.998, 99.96th percentile). The record does not confirm public exploit availability.

What to do

  • Apply vendor updates for the affected antivirus and scanning engines; this is a 2012 issue, so confirm current versions are not still affected.
  • Where a vendor never patched, replace or upgrade the affected TAR parsing component or scanning engine.
  • Do not rely on a single AV engine for TAR archives; add a second, independently implemented scanner or sandbox detonation.
  • Block or quarantine inbound TAR archives at mail and web gateways until scanning is verified against crafted-entry test cases.
  • Re-test detection with a TAR archive containing an entry length field that overlaps the next entry header.

Detection

  • Hunt for TAR archives whose entry length fields extend beyond the entry into the following header, using a parser that logs such anomalies.
  • Monitor AV and gateway logs for archives that pass scanning but later trigger endpoint alerts or sandbox detonation.
  • Alert on TAR files arriving from external sources that contain executables or scripts, regardless of scan verdict.
  • Track scanner engine versions against vendor advisories for this TAR parsing flaw.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

34 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1459 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-2869Alwil avast antivirus vulnerabilityUnspecified vulnerability in the CHM unpacker in avast! before 4.7.844 has unknown impact and remote attack vectors.EPSS 1.7%9.3CVE-2008-5520Ahnlab v3 internet security improper input validation vulnerabilityAhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an H…EPSS 1.9%9.3CVE-2007-6060Ahnlab v3 internet security improper input validation vulnerabilityAhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP …EPSS 5.7%9.3CVE-2007-2917Authentium command antivirus vulnerabilityMultiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute a…EPSS 6.6%7.8CVE-2013-3947Ahnlab v3 internet security memory buffer overflow vulnerabilityBuffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IO…EPSS 0.48%7.5CVE-2006-4626Alwil avast antivirus vulnerabilityHeap-based buffer overflow in alwil avast! Anti-virus Engine before 4.7.869 allows remote attackers to execute arbitrary code via a crafted LHA file …EPSS 4.7%7.5CVE-2005-2385Alwil avast antivirus vulnerabilityBuffer overflow in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition …EPSS 4.0%7.5CVE-2005-1719Alwil avast antivirus vulnerabilityUnknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2012-1459), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.