Vulnerability record · CVE-2012-1460 · published 21 March 2012
CVE-2012-1460: Gzip parser in multiple antivirus engines allows malware detection bypass
Aladdin · Esafe
The Gzip file parser in several antivirus products mishandles .tar.gz archives containing stray bytes at the end, allowing malware to evade detection. The flaw affects multiple independent engines (Antiy AVL SDK, Quick Heal, Command Antivirus, eSafe, F-Prot, Jiangmin, K7, VBA32), so a single crafted archive can slip past several scanners at once. It matters because detection bypass undermines the core protective function of these products.
Description
The Gzip file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with stray bytes at the end. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityIt is a detection bypass rather than direct code execution (CVSS 4.3), but it affects many widely deployed scanners and carries a very high EPSS score.
What it is
The Gzip file parser in several antivirus products mishandles .tar.gz archives containing stray bytes at the end, allowing malware to evade detection. The flaw affects multiple independent engines (Antiy AVL SDK, Quick Heal, Command Antivirus, eSafe, F-Prot, Jiangmin, K7, VBA32), so a single crafted archive can slip past several scanners at once. It matters because detection bypass undermines the core protective function of these products.
Impact
An attacker can deliver a malicious .tar.gz that the affected scanner fails to flag, letting malware reach the endpoint or mail gateway undetected. The attacker gains no code execution from the flaw itself, only evasion of the antivirus check.
Attack surface
Reached remotely by supplying a crafted .tar.gz file to a system whose antivirus engine parses it, such as through email attachments, web downloads or file uploads. No authentication is required, but some user or automated action to deliver and scan the file is needed (AV:N/AC:M/Au:N).
Exploitation
Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, though EPSS is very high (0.944, 99.8th percentile), indicating strong predicted likelihood of exploitation activity.
What to do
- Apply vendor updates for each affected antivirus engine; the record does not list fixed versions, so confirm with each vendor.
- Where no fix exists, disable or restrict automatic parsing of .tar.gz archives by the scanner and route them to a secondary inspection tool.
- Add independent detection layers (sandboxing, YARA or signature checks outside the affected parser) so a single bypass does not result in delivery.
- Block or quarantine .tar.gz attachments at the mail and web gateway unless explicitly required.
- Track the NVD note that this CVE may be split per implementation and re-check advisories for each product.
Detection
- Monitor for .tar.gz files with trailing stray bytes after the gzip stream and alert on scanner results that return clean for such files.
- Correlate antivirus scan logs with file delivery events to find archives that pass scanning but later execute or drop payloads.
- Hunt for repeated submissions of malformed .tar.gz archives to mail gateways or upload endpoints from the same source.
- Review endpoint telemetry for processes spawned from extracted archive contents that were never flagged by the local scanner.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1460 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1460), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.