Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-0278

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2012-0278
Last Modified 14 Feb 2013 11:53:02
Published 18 Apr 2012 06:33:32
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2012-0278

Summary

Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.

Vulnerable Systems

Application

  • Irfanview Flashpix Plugin 4.32

  • Irfanview Flashpix Plugin 4.33


References

MISC - http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=41&Itemid=41

SECUNIA - 48772

BID - 53009


Last Updated: 27 May 2016 10:57:30