20120629 Irfanview Plugins JLS Decompressionmailing list
http://archives.neohapsis.com/archives/bugtraq/2012-06/0191.html CVE-2012-3585
IrfanView JLS Formats PlugIn - Heap Overflow
Record summary
CVE-2012-3585 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Heap-based buffer overflow in jpeg_ls.dll in the Jpeg_LS (aka JLS) plugin in the formats plugins in IrfanView PlugIns before 4.34 allows remote attackers to execute arbitrary code via a crafted JLS file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBIrfanView JLS Formats PlugIn - Heap OverflowExploitDB exploitby Joseph SheridanNot analyzed1 file
References
3reactionpenetrationtesting.co.uk
http://www.reactionpenetrationtesting.co.uk/Irfanview-JLS-Heap-Overflow.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-3585