Vulnerability record · CVE-2012-1459 · published 21 March 2012
CVE-2012-1459: TAR parser malware detection bypass in multiple antivirus products
Ahnlab · V3 Internet Security
The TAR file parser in dozens of antivirus products mishandles a TAR archive entry whose length field spans the entire entry plus part of the next entry's header. This lets a crafted archive evade malware detection, so malicious content passes through scanning undetected. The record covers many independent vendor implementations and may later be split into separate CVEs.
Description
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityCVSS 2.0 is 4.3 (MEDIUM) and the flaw only bypasses detection rather than executing code, but it affects a very broad set of security products and EPSS is extremely high.
What it is
The TAR file parser in dozens of antivirus products mishandles a TAR archive entry whose length field spans the entire entry plus part of the next entry's header. This lets a crafted archive evade malware detection, so malicious content passes through scanning undetected. The record covers many independent vendor implementations and may later be split into separate CVEs.
Impact
An attacker can deliver malware inside a crafted TAR archive that the affected scanner fails to flag, defeating the primary detection control. No code execution or data modification on the scanner host is described; the gain is evasion of malware detection.
Attack surface
Reached remotely by supplying a malicious TAR archive to a scanning interface, as reflected by the AV:N network vector. No authentication is required (Au:N), but exploitation depends on the target processing the crafted archive, which the AC:M vector indicates is not fully reliable.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, though EPSS is very high (0.998, 99.96th percentile). The record does not confirm public exploit availability.
What to do
- Apply vendor updates for the affected antivirus and scanning engines; this is a 2012 issue, so confirm current versions are not still affected.
- Where a vendor never patched, replace or upgrade the affected TAR parsing component or scanning engine.
- Do not rely on a single AV engine for TAR archives; add a second, independently implemented scanner or sandbox detonation.
- Block or quarantine inbound TAR archives at mail and web gateways until scanning is verified against crafted-entry test cases.
- Re-test detection with a TAR archive containing an entry length field that overlaps the next entry header.
Detection
- Hunt for TAR archives whose entry length fields extend beyond the entry into the following header, using a parser that logs such anomalies.
- Monitor AV and gateway logs for archives that pass scanning but later trigger endpoint alerts or sandbox detonation.
- Alert on TAR files arriving from external sources that contain executables or scripts, regardless of scan verdict.
- Track scanner engine versions against vendor advisories for this TAR parsing flaw.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
34 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1459 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1459), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.