CVE-2012-0278: Buffer Overflow
Published Apr 18, 2012
·Updated
Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.
Affected Software
3 affected components
IrfanView FlashPix PlugIn<=4.33
IrfanView FlashPix PlugIn=4.32
IrfanView IrfanView
Event History
Apr 18, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0278?
CVE-2012-0278 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2012-0278?
To fix CVE-2012-0278, you should update the FlashPix PlugIn to version 4.3.4.0 or later.
3
What software is affected by CVE-2012-0278?
CVE-2012-0278 affects FlashPix PlugIn versions 4.32 and earlier for IrfanView.
4
How does CVE-2012-0278 work?
CVE-2012-0278 works by exploiting a heap-based buffer overflow when handling crafted .fpx files.
5
Who can exploit CVE-2012-0278?
CVE-2012-0278 can be exploited by remote attackers who can deliver a specially crafted FlashPix image.