CVE-2012-0025: Double Free
Published Nov 2, 2012
·Updated
Double free vulnerability in the FreeAllMemory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image.
Affected Software
1 affected component
IrfanView FlashPix PlugIn=4.2.2.0
Event History
Nov 2, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0025?
CVE-2012-0025 has a moderate severity rating due to the potential for denial of service attacks.
2
How do I fix CVE-2012-0025?
To mitigate CVE-2012-0025, update the FlashPix plugin to version 4.2.2.1 or later.
3
Which software is affected by CVE-2012-0025?
CVE-2012-0025 affects the FlashPix Plugin version 4.2.2.0 for IrfanView.
4
What type of vulnerability is CVE-2012-0025?
CVE-2012-0025 is classified as a double free vulnerability.
5
Can CVE-2012-0025 be exploited remotely?
Yes, CVE-2012-0025 can be exploited remotely through crafted FPX images.