The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial ITSF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
| Software | From | Fixed in |
|---|---|---|
| norman / norman_antivirus_&_antispyware | 6.06.12 | 6.06.12.x |
| rising-global / rising_antivirus | 22.83.00.03 | 22.83.00.03.x |
| eset / nod32_antivirus | 5795 | 5795.x |
| cat / quick_heal | 11.00 | 11.00.x |