First published: Fri Nov 02 2012(Updated: )
Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView FlashPix Plugin | =4.2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0025 has a moderate severity rating due to the potential for denial of service attacks.
To mitigate CVE-2012-0025, update the FlashPix plugin to version 4.2.2.1 or later.
CVE-2012-0025 affects the FlashPix Plugin version 4.2.2.0 for IrfanView.
CVE-2012-0025 is classified as a double free vulnerability.
Yes, CVE-2012-0025 can be exploited remotely through crafted FPX images.