First published: Thu Jul 05 2012(Updated: )
Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attackers to execute arbitrary code via a crafted JLS file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView | <=4.33 | |
IrfanView |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3585 is considered critical due to its potential for remote code execution.
To fix CVE-2012-3585, users should update to IrfanView PlugIns version 4.34 or later.
CVE-2012-3585 affects IrfanView PlugIns versions prior to 4.34 and the Jpeg_LS plugin.
CVE-2012-3585 is a heap-based buffer overflow vulnerability.
Yes, CVE-2012-3585 can be exploited remotely through a crafted JLS file.