---
title: "CVE-2012-1459\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-1459?format=md
keywords: index, follow
---

# CVE-2012-1459

Publication date 21 March 2012

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira
AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0
and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka
Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo
Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117,
F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data
AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0,
Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus
7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway
(formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft
Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12,
nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools
AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0,
AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro
AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32
3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass
malware detection via a TAR archive entry with a length field corresponding
to that entire entry, plus part of the header of the next entry. NOTE:
this may later be SPLIT into multiple CVEs if additional information is
published showing that the error occurred independently in different TAR
parser implementations.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| clamav | 12.04 LTS precise | Fixed 0.97.5+dfsg-1ubuntu0.12.04.1 |
| 11.10 oneiric | Fixed 0.97.5+dfsg-1ubuntu0.11.10.1 |
| 11.04 natty | Fixed 0.97.5+dfsg-1ubuntu0.11.04.1 |
| 10.10 maverick | Ignored end of life |
| 10.04 LTS lucid | Fixed 0.96.5+dfsg-1ubuntu1.10.04.4 |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2012-1459?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| clamav | * Upstream:   <http://git.clamav.net/gitweb?p=clamav-devel.git;a=commit;h=c3c807d78b09b3f64630601002fdc7db257d89da> * Upstream:   <http://git.clamav.net/gitweb?p=clamav-devel.git;a=commit;h=9d6be7c56091f012e90074122db4ec12d3516011> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1459)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-1459)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-1459)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-1459)

### Related Ubuntu Security Notices (USN)

+ [USN-1482-1](https://usn.ubuntu.com/USN-1482-1)
+ ClamAV vulnerabilities
+ 19 June 2012

### Other references

* <http://www.ieee-security.org/TC/SP2012/program.html>
* <https://www.cve.org/CVERecord?id=CVE-2012-1459>
