CVE-2012-1420: Authentium Command Antivirus
Medium severity, CVSS 4.3. EPSS: 97.1% chance of exploitation in the next 30 days.
The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
Affected products
- Authentium Command Antivirus: version 5.2.11.5 only
- Cat Quick Heal: version 11.00 only
- Eset NOD32 Antivirus: version 5795 only
- F-Prot F-Prot Antivirus: version 4.6.2.117 only
- Fortinet Fortinet Antivirus: version 4.2.254.0 only
- k7computing Antivirus: version 9.77.3565 only
- Kaspersky Kaspersky Anti-Virus: version 7.0.0.125 only
- Microsoft Security Essentials: version 2.0 only
- Norman Norman Antivirus & Antispyware: version 6.06.12 only
- Pandasecurity Panda Antivirus: version 10.0.2.7 only
- Rising-Global Rising Antivirus: version 22.83.00.03 only
Published 2012-03-21. Last modified 2026-06-16.