CVE-2012-0897 describes a stack-based buffer overflow vulnerability in the JPEG2000 plugin of IrfanView PlugIns prior to version 4.33. This flaw allows remote attackers to execute arbitrary code by crafting a malicious JPEG2000 (JP2) file with a specially designed Quantization Default (QCD) marker segment. The vulnerability has a CVSS score of 6.8, indicating a medium severity, and is easily exploitable over a network with moderate attack complexity, potentially leading to partial confidentiality, integrity, and availability impacts. While not on the KEV catalog, a Metasploit module exists for this vulnerability, and it has garnered some community discussion and media coverage, suggesting awareness and the availability of exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.32CPE matchmatch criteria | cpe:2.3:a:irfanview:irfanview:*:*:*:*:*:*:*:* | ||
1.70CPE matchmatch criteria | cpe:2.3:a:irfanview:irfanview:1.70:*:*:*:*:*:*:* | ||
1.75CPE matchmatch criteria | cpe:2.3:a:irfanview:irfanview:1.75:*:*:*:*:*:*:* | ||
1.80CPE matchmatch criteria | cpe:2.3:a:irfanview:irfanview:1.80:*:*:*:*:*:*:* | ||
1.85CPE matchmatch criteria | cpe:2.3:a:irfanview:irfanview:1.85:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.