First published: Wed Mar 21 2012(Updated: )
The TAR file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Jiangmin Antivirus 13.0.900, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Antiy AVL SDK | =2.0.3.7 | |
QuickHeal CAT QuickHeal | =11.00 | |
Jiangmin Jiangmin Antivirus | =13.0.900 | |
Norman Antivirus & Antispyware | =6.06.12 | |
PC Tools Antivirus | =7.0.3.5 | |
Sophos Anti-Virus | =4.61.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1424 is considered a high severity vulnerability as it allows attackers to bypass malware detection.
To fix CVE-2012-1424, update affected antivirus software to the latest version provided by the vendor.
CVE-2012-1424 affects Antiy AVL SDK 2.0.3.7, Quick Heal 11.00, Jiangmin Antivirus 13.0.900, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, and Sophos Anti-Virus 4.61.0.
Yes, CVE-2012-1424 can be exploited remotely by attackers through a specially crafted POSIX TAR file.
The impact of CVE-2012-1424 is that it allows malicious files to evade detection, potentially compromising system security.