<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">CVE-2012-1459</DocumentTitle>
  <DocumentType>SUSE CVE</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE CVE-2012-1459</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>25</Number>
        <Date>2025-11-05T05:40:12Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-05-30T13:02:41Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-11-05T05:40:12Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-cve.pl</Engine>
      <Date>2020-12-27T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="CVE" Type="Summary" Ordinal="1" xml:lang="en">CVE-2012-1459</Note>
    <Note Title="Mitre CVE Description" Type="Description" Ordinal="2" xml:lang="en">The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry.  NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="4" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2012-July/000176.html</URL>
      <Description>E-Mail link for SUSE-SU-2012:0858-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VRBJPUXQRYMY6BHNDKNSD5LQIMQCPBXN/#VRBJPUXQRYMY6BHNDKNSD5LQIMQCPBXN</URL>
      <Description>E-Mail link for openSUSE-SU-2012:0833-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="SUSE Enterprise Storage 6">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP1" CPE="cpe:/o:suse:sle-module-basesystem:15:sp1">SUSE Linux Enterprise Module for Basesystem 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 12">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 12" CPE="cpe:/o:suse:sled:12">SUSE Linux Enterprise Desktop 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1" CPE="cpe:/o:suse:sled:12:sp1">SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP2" CPE="cpe:/o:suse:sled:12:sp2">SUSE Linux Enterprise Desktop 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 12 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP3" CPE="cpe:/o:suse:sled:12:sp3">SUSE Linux Enterprise Desktop 12 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 12 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 12 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP4" CPE="cpe:/o:suse:sled:12:sp4">SUSE Linux Enterprise Desktop 12 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15" CPE="cpe:/o:suse:sle-module-basesystem:15">SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 15 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP1" CPE="cpe:/o:suse:sle-module-basesystem:15:sp1">SUSE Linux Enterprise Module for Basesystem 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 12 SP5" CPE="cpe:/o:suse:sle-hpc:12:sp5">SUSE Linux Enterprise High Performance Computing 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15" CPE="cpe:/o:suse:sle-module-basesystem:15">SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP1" CPE="cpe:/o:suse:sle-module-basesystem:15:sp1">SUSE Linux Enterprise Module for Basesystem 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP1-TERADATA">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP1-TERADATA">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP1-TERADATA" CPE="cpe:/o:suse:sles:11:sp1:teradata">SUSE Linux Enterprise Server 11 SP1-TERADATA</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3" CPE="cpe:/o:suse:suse_sles:11:sp3">SUSE Linux Enterprise Server 11 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 11 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 11 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4" CPE="cpe:/o:suse:suse_sles:11:sp4">SUSE Linux Enterprise Server 11 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12" CPE="cpe:/o:suse:sles:12">SUSE Linux Enterprise Server 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1" CPE="cpe:/o:suse:sles:12:sp1">SUSE Linux Enterprise Server 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2" CPE="cpe:/o:suse:sles:12:sp2">SUSE Linux Enterprise Server 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3" CPE="cpe:/o:suse:sles:12:sp3">SUSE Linux Enterprise Server 12 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4" CPE="cpe:/o:suse:sles:12:sp4">SUSE Linux Enterprise Server 12 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5" CPE="cpe:/o:suse:sles:12:sp5">SUSE Linux Enterprise Server 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15" CPE="cpe:/o:suse:sle-module-basesystem:15">SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP1" CPE="cpe:/o:suse:sle-module-basesystem:15:sp1">SUSE Linux Enterprise Module for Basesystem 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 16.0">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 16.0">
        <FullProductName ProductID="SUSE Linux Enterprise Server 16.0" CPE="cpe:/o:suse:sles:16.0">SUSE Linux Enterprise Server 16.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2" CPE="cpe:/o:suse:sles:12:sp2">SUSE Linux Enterprise Server for Raspberry Pi 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5" CPE="cpe:/o:suse:sles_sap:12:sp5">SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15" CPE="cpe:/o:suse:sle-module-basesystem:15">SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP1" CPE="cpe:/o:suse:sle-module-basesystem:15:sp1">SUSE Linux Enterprise Module for Basesystem 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Proxy 4.0">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP1" CPE="cpe:/o:suse:sle-module-basesystem:15:sp1">SUSE Linux Enterprise Module for Basesystem 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Retail Branch Server 4.0">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP1" CPE="cpe:/o:suse:sle-module-basesystem:15:sp1">SUSE Linux Enterprise Module for Basesystem 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Server 4.0">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Basesystem 15 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP1" CPE="cpe:/o:suse:sle-module-basesystem:15:sp1">SUSE Linux Enterprise Module for Basesystem 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.100.0-1.17">
      <FullProductName ProductID="clamav-0.100.0-1.17" CPE="cpe:2.3:a:clamav:clamav:0.100.0:*:*:*:*:*:*:*">clamav-0.100.0-1.17</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.100.2-33.18.1">
      <FullProductName ProductID="clamav-0.100.2-33.18.1" CPE="cpe:2.3:a:clamav:clamav:0.100.2:*:*:*:*:*:*:*">clamav-0.100.2-33.18.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.100.3-3.9.1">
      <FullProductName ProductID="clamav-0.100.3-3.9.1" CPE="cpe:2.3:a:clamav:clamav:0.100.3:*:*:*:*:*:*:*">clamav-0.100.3-3.9.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.101.3-1.19">
      <FullProductName ProductID="clamav-0.101.3-1.19" CPE="cpe:2.3:a:clamav:clamav:0.101.3:*:*:*:*:*:*:*">clamav-0.101.3-1.19</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.97.5-0.2.1">
      <FullProductName ProductID="clamav-0.97.5-0.2.1" CPE="cpe:2.3:a:clamav:clamav:0.97.5:*:*:*:*:*:*:*">clamav-0.97.5-0.2.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.97.7-0.3.1">
      <FullProductName ProductID="clamav-0.97.7-0.3.1" CPE="cpe:2.3:a:clamav:clamav:0.97.7:*:*:*:*:*:*:*">clamav-0.97.7-0.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.98.4-1.46">
      <FullProductName ProductID="clamav-0.98.4-1.46" CPE="cpe:2.3:a:clamav:clamav:0.98.4:*:*:*:*:*:*:*">clamav-0.98.4-1.46</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.98.7-0.3.1">
      <FullProductName ProductID="clamav-0.98.7-0.3.1" CPE="cpe:2.3:a:clamav:clamav:0.98.7:*:*:*:*:*:*:*">clamav-0.98.7-0.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.98.7-13.1">
      <FullProductName ProductID="clamav-0.98.7-13.1" CPE="cpe:2.3:a:clamav:clamav:0.98.7:*:*:*:*:*:*:*">clamav-0.98.7-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.99.2-25.1">
      <FullProductName ProductID="clamav-0.99.2-25.1" CPE="cpe:2.3:a:clamav:clamav:0.99.2:*:*:*:*:*:*:*">clamav-0.99.2-25.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.99.2-32.1">
      <FullProductName ProductID="clamav-0.99.2-32.1" CPE="cpe:2.3:a:clamav:clamav:0.99.2:*:*:*:*:*:*:*">clamav-0.99.2-32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-0.99.2-4.1">
      <FullProductName ProductID="clamav-0.99.2-4.1" CPE="cpe:2.3:a:clamav:clamav:0.99.2:*:*:*:*:*:*:*">clamav-0.99.2-4.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-1.4.3-160000.2.2">
      <FullProductName ProductID="clamav-1.4.3-160000.2.2" CPE="cpe:2.3:a:clamav:clamav:1.4.3:*:*:*:*:*:*:*">clamav-1.4.3-160000.2.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-devel-0.100.0-1.17">
      <FullProductName ProductID="clamav-devel-0.100.0-1.17">clamav-devel-0.100.0-1.17</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-devel-0.100.3-3.9.1">
      <FullProductName ProductID="clamav-devel-0.100.3-3.9.1">clamav-devel-0.100.3-3.9.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-devel-1.4.3-160000.2.2">
      <FullProductName ProductID="clamav-devel-1.4.3-160000.2.2">clamav-devel-1.4.3-160000.2.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-docs-html-1.4.3-160000.2.2">
      <FullProductName ProductID="clamav-docs-html-1.4.3-160000.2.2">clamav-docs-html-1.4.3-160000.2.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="clamav-milter-1.4.3-160000.2.2">
      <FullProductName ProductID="clamav-milter-1.4.3-160000.2.2">clamav-milter-1.4.3-160000.2.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libclamav12-1.4.3-160000.2.2">
      <FullProductName ProductID="libclamav12-1.4.3-160000.2.2">libclamav12-1.4.3-160000.2.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libclamav7-0.100.0-1.17">
      <FullProductName ProductID="libclamav7-0.100.0-1.17">libclamav7-0.100.0-1.17</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libclamav7-0.100.3-3.9.1">
      <FullProductName ProductID="libclamav7-0.100.3-3.9.1">libclamav7-0.100.3-3.9.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libclammspack0-0.100.0-1.17">
      <FullProductName ProductID="libclammspack0-0.100.0-1.17">libclammspack0-0.100.0-1.17</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libclammspack0-0.100.3-3.9.1">
      <FullProductName ProductID="libclammspack0-0.100.3-3.9.1">libclammspack0-0.100.3-3.9.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libclammspack0-1.4.3-160000.2.2">
      <FullProductName ProductID="libclammspack0-1.4.3-160000.2.2">libclammspack0-1.4.3-160000.2.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libfreshclam3-1.4.3-160000.2.2">
      <FullProductName ProductID="libfreshclam3-1.4.3-160000.2.2">libfreshclam3-1.4.3-160000.2.2</FullProductName>
    </Branch>
    <Relationship ProductReference="clamav-0.98.4-1.46" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12:clamav-0.98.4-1.46">clamav-0.98.4-1.46 as a component of SUSE Linux Enterprise Desktop 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.98.7-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP1:clamav-0.98.7-13.1">clamav-0.98.7-13.1 as a component of SUSE Linux Enterprise Desktop 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.99.2-25.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP2:clamav-0.99.2-25.1">clamav-0.99.2-25.1 as a component of SUSE Linux Enterprise Desktop 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.99.2-32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP3:clamav-0.99.2-32.1">clamav-0.99.2-32.1 as a component of SUSE Linux Enterprise Desktop 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.100.2-33.18.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP4:clamav-0.100.2-33.18.1">clamav-0.100.2-33.18.1 as a component of SUSE Linux Enterprise Desktop 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.101.3-1.19" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 12 SP5:clamav-0.101.3-1.19">clamav-0.101.3-1.19 as a component of SUSE Linux Enterprise High Performance Computing 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.100.0-1.17" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15:clamav-0.100.0-1.17">clamav-0.100.0-1.17 as a component of SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-devel-0.100.0-1.17" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15:clamav-devel-0.100.0-1.17">clamav-devel-0.100.0-1.17 as a component of SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libclamav7-0.100.0-1.17" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15:libclamav7-0.100.0-1.17">libclamav7-0.100.0-1.17 as a component of SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="libclammspack0-0.100.0-1.17" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15:libclammspack0-0.100.0-1.17">libclammspack0-0.100.0-1.17 as a component of SUSE Linux Enterprise Module for Basesystem 15</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.100.3-3.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP1:clamav-0.100.3-3.9.1">clamav-0.100.3-3.9.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-devel-0.100.3-3.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP1:clamav-devel-0.100.3-3.9.1">clamav-devel-0.100.3-3.9.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libclamav7-0.100.3-3.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP1:libclamav7-0.100.3-3.9.1">libclamav7-0.100.3-3.9.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libclammspack0-0.100.3-3.9.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Basesystem 15 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Basesystem 15 SP1:libclammspack0-0.100.3-3.9.1">libclammspack0-0.100.3-3.9.1 as a component of SUSE Linux Enterprise Module for Basesystem 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.97.5-0.2.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP1-TERADATA">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP1-TERADATA:clamav-0.97.5-0.2.1">clamav-0.97.5-0.2.1 as a component of SUSE Linux Enterprise Server 11 SP1-TERADATA</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.97.7-0.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP3:clamav-0.97.7-0.3.1">clamav-0.97.7-0.3.1 as a component of SUSE Linux Enterprise Server 11 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.98.7-0.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 11 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server 11 SP4:clamav-0.98.7-0.3.1">clamav-0.98.7-0.3.1 as a component of SUSE Linux Enterprise Server 11 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.98.4-1.46" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12:clamav-0.98.4-1.46">clamav-0.98.4-1.46 as a component of SUSE Linux Enterprise Server 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.98.7-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1:clamav-0.98.7-13.1">clamav-0.98.7-13.1 as a component of SUSE Linux Enterprise Server 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.99.2-25.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:clamav-0.99.2-25.1">clamav-0.99.2-25.1 as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.99.2-32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3:clamav-0.99.2-32.1">clamav-0.99.2-32.1 as a component of SUSE Linux Enterprise Server 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.100.2-33.18.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4:clamav-0.100.2-33.18.1">clamav-0.100.2-33.18.1 as a component of SUSE Linux Enterprise Server 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.101.3-1.19" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:clamav-0.101.3-1.19">clamav-0.101.3-1.19 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-1.4.3-160000.2.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:clamav-1.4.3-160000.2.2">clamav-1.4.3-160000.2.2 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-devel-1.4.3-160000.2.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:clamav-devel-1.4.3-160000.2.2">clamav-devel-1.4.3-160000.2.2 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-docs-html-1.4.3-160000.2.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:clamav-docs-html-1.4.3-160000.2.2">clamav-docs-html-1.4.3-160000.2.2 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-milter-1.4.3-160000.2.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:clamav-milter-1.4.3-160000.2.2">clamav-milter-1.4.3-160000.2.2 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="libclamav12-1.4.3-160000.2.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:libclamav12-1.4.3-160000.2.2">libclamav12-1.4.3-160000.2.2 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="libclammspack0-1.4.3-160000.2.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:libclammspack0-1.4.3-160000.2.2">libclammspack0-1.4.3-160000.2.2 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfreshclam3-1.4.3-160000.2.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 16.0">
      <FullProductName ProductID="SUSE Linux Enterprise Server 16.0:libfreshclam3-1.4.3-160000.2.2">libfreshclam3-1.4.3-160000.2.2 as a component of SUSE Linux Enterprise Server 16.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.99.2-25.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:clamav-0.99.2-25.1">clamav-0.99.2-25.1 as a component of SUSE Linux Enterprise Server for Raspberry Pi 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.101.3-1.19" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:clamav-0.101.3-1.19">clamav-0.101.3-1.19 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="clamav-0.99.2-4.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:clamav-0.99.2-4.1">clamav-0.99.2-4.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry.  NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.</Note>
    </Notes>
    <CVE>CVE-2012-1459</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:clamav-0.98.4-1.46</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP1:clamav-0.98.7-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:clamav-0.99.2-25.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:clamav-0.99.2-32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP4:clamav-0.100.2-33.18.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 12 SP5:clamav-0.101.3-1.19</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15:clamav-0.100.0-1.17</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15:clamav-devel-0.100.0-1.17</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15:libclamav7-0.100.0-1.17</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15:libclammspack0-0.100.0-1.17</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15 SP1:clamav-0.100.3-3.9.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15 SP1:clamav-devel-0.100.3-3.9.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15 SP1:libclamav7-0.100.3-3.9.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Basesystem 15 SP1:libclammspack0-0.100.3-3.9.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP1-TERADATA:clamav-0.97.5-0.2.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP3:clamav-0.97.7-0.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 11 SP4:clamav-0.98.7-0.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:clamav-0.98.4-1.46</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1:clamav-0.98.7-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:clamav-0.99.2-25.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:clamav-0.99.2-32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4:clamav-0.100.2-33.18.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:clamav-0.101.3-1.19</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:clamav-1.4.3-160000.2.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:clamav-devel-1.4.3-160000.2.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:clamav-docs-html-1.4.3-160000.2.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:clamav-milter-1.4.3-160000.2.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:libclamav12-1.4.3-160000.2.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:libclammspack0-1.4.3-160000.2.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 16.0:libfreshclam3-1.4.3-160000.2.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:clamav-0.99.2-25.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:clamav-0.101.3-1.19</ProductID>
        <ProductID>openSUSE Tumbleweed:clamav-0.99.2-4.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:P/A:N</VectorV2>
      </ScoreSetV2>
    </CVSSScoreSets>
  </Vulnerability>
</cvrfdoc>
