Contact Us
SECURITY BLOG SECURITY DASHBOARD PARTNERS PRODUCTS JOBS SERVICES COMPANY HOME
Network Security Consulting Advisories Article

IrfanView Formats PlugIn 'jpeg_ls.dll' Heap Buffer Overflow Vulnerability

http://www.securityfocus.com/bid/54244

Security Info

Bugtraq ID: 54244
Class: Boundary Condition Error
CVE: CVE-2012-3585
Remote: Yes
Local: No
Published: Jun 29 2012 12:00AM
Updated: Jun 29 2012 12:00AM
Credit: Joseph Sheridan
Vulnerable: IrfanView Formats PlugIn 4.33
Not Vulnerable: IrfanView Formats PlugIn 4.34

Security Discussion

The Formats PlugIn for IrfanView is prone to a remote heap-based buffer-overflow vulnerability because the software fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.

Successful exploits allow remote attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts likely result in denial-of-service conditions.

Formats PlugIn 4.33 is vulnerable; other versions may also be affected.

Proof of Concept and Security Exploits

The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.

Security Solution(s)

Solution:
Updates are available. Please see the references for more details.

Security References(s)

References:

Contact Us

Security Penetration Testing

Security Questions

Security Dashboard

Emagined Security Blog featuring Dr. Eugene Schultz
Site Updated May 25, 2013
©2000-2013 Emagined Security
All Rights Reserved

Secure Web Programming
by Vizual Services