9.3
CVSSv2

CVE-2012-3585

Published: 05/07/2012 Updated: 17/07/2012
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns prior to 4.34 allows remote malicious users to execute arbitrary code via a crafted JLS file.

Vulnerable Product Search on Vulmon Subscribe to Product

irfanview irfanview_plugins

Exploits

Summary ======= IrfanView Formats PlugIn is prone to an overflow condition The JLS Plugin (jpeg_lsdll) library fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow With a specially crafted JLS compressed image file, a context-dependent attacker could potentially execute arbitrary code CVE number: CVE-20 ...