CVE-2012-1424: Antiy Avl SDK
Medium severity, CVSS 4.3. EPSS: 87.3% chance of exploitation in the next 30 days.
The TAR file parser in Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Jiangmin Antivirus 13.0.900, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a POSIX TAR file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
Affected products
- Antiy Avl SDK: version 2.0.3.7 only
- Cat Quick Heal: version 11.00 only
- Jiangmin Jiangmin Antivirus: version 13.0.900 only
- Norman Norman Antivirus & Antispyware: version 6.06.12 only
- Pc Tools Pc Tools Antivirus: version 7.0.3.5 only
- Sophos Sophos Anti-Virus: version 4.61.0 only
Published 2012-03-21. Last modified 2026-06-16.