Executive Summary

Informations
Name CVE-2012-0897 First vendor Publication 2012-01-20
Vendor Cve Last vendor Modification 2017-08-29

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0897

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:22613
 
Oval ID: oval:org.mitre.oval:def:22613
Title: Vulnerability in IrfanView before 4.33 in stack-based buffer overflow in the JPEG2000 plugin
Description: Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.
Family: windows Class: vulnerability
Reference(s): CVE-2012-0897
Version: 5
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s): IrfanView
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 86

OpenVAS Exploits

Date Description
2012-02-01 Name : IrfanView JPEG-2000 Plugin Remote Stack Based Buffer Overflow Vulnerability
File : nvt/gb_irfanview_jpeg2000_bof_vuln.nasl

Information Assurance Vulnerability Management (IAVM)

Date Description
2015-06-18 IAVM : 2015-B-0076 - Multiple Vulnerabilities in VMware Horizon View Client
Severity : Category I - VMSKEY : V0060965
2015-06-18 IAVM : 2015-B-0077 - VMware Fusion Denial of Service Vulnerability
Severity : Category I - VMSKEY : V0060979

Snort® IPS/IDS

Date Description
2015-07-28 VMWare Workstation JPEG2000 stack overflow attempt
RuleID : 34987 - Revision : 3 - Type : FILE-OTHER
2015-07-28 VMWare Workstation JPEG2000 stack overflow attempt
RuleID : 34986 - Revision : 3 - Type : FILE-OTHER
2015-07-28 VMWare Workstation JPEG2000 stack overflow attempt
RuleID : 34985 - Revision : 3 - Type : FILE-OTHER
2015-07-28 VMWare Workstation JPEG2000 stack overflow attempt
RuleID : 34984 - Revision : 3 - Type : FILE-OTHER

Nessus® Vulnerability Scanner

Date Description
2015-06-16 Name : A VMware product installed on the remote host is affected by a denial of serv...
File : macosx_fusion_7_0_1.nasl - Type : ACT_GATHER_INFO
2015-06-16 Name : The remote host has a virtualization application installed that is affected b...
File : vmware_player_6_0_6_vmsa_2015-0004.nasl - Type : ACT_GATHER_INFO
2015-06-16 Name : The remote host has a virtualization application installed that is affected b...
File : vmware_player_7_1_1_vmsa_2015-0004.nasl - Type : ACT_GATHER_INFO
2015-06-16 Name : The remote host has a virtualization application installed that is affected b...
File : vmware_player_linux_6_0_6.nasl - Type : ACT_GATHER_INFO
2015-06-16 Name : The remote host has a virtualization application installed that is affected b...
File : vmware_workstation_linux_10_0_6.nasl - Type : ACT_GATHER_INFO
2015-06-16 Name : The remote host has a virtualization application installed that is affected b...
File : vmware_workstation_multiple_vmsa_2015_0004.nasl - Type : ACT_GATHER_INFO
2015-06-12 Name : The remote host has a virtual desktop solution installed that is affected by ...
File : vmware_horizon_view_client_vmsa_2015_0004.nasl - Type : ACT_GATHER_INFO
2015-02-05 Name : The remote host has a virtualization application installed that is affected b...
File : vmware_workstation_multiple_vmsa_2015_0001.nasl - Type : ACT_GATHER_INFO
2015-01-23 Name : The remote OracleVM host is missing one or more security updates.
File : oraclevm_OVMSA-2015-0004.nasl - Type : ACT_GATHER_INFO
2012-07-05 Name : The remote host has an application installed that is affected by a stack-base...
File : irfanview_jpeg2000_stack_overflow.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/51426
CONFIRM http://www.irfanview.com/history_old.htm
OSVDB http://osvdb.org/78333
SECTRACK http://www.securitytracker.com/id/1032529
http://www.securitytracker.com/id/1032530
SECUNIA http://secunia.com/advisories/47360
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/72398

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
Date Informations
2024-02-02 01:18:35
  • Multiple Updates
2024-02-01 12:05:30
  • Multiple Updates
2023-09-05 12:17:32
  • Multiple Updates
2023-09-05 01:05:23
  • Multiple Updates
2023-09-02 12:17:33
  • Multiple Updates
2023-09-02 01:05:29
  • Multiple Updates
2023-08-12 12:21:17
  • Multiple Updates
2023-08-12 01:05:30
  • Multiple Updates
2023-08-11 12:17:39
  • Multiple Updates
2023-08-11 01:05:39
  • Multiple Updates
2023-08-06 12:16:58
  • Multiple Updates
2023-08-06 01:05:30
  • Multiple Updates
2023-08-04 12:17:02
  • Multiple Updates
2023-08-04 01:05:32
  • Multiple Updates
2023-07-14 12:17:01
  • Multiple Updates
2023-07-14 01:05:27
  • Multiple Updates
2023-03-29 01:18:58
  • Multiple Updates
2023-03-28 12:05:36
  • Multiple Updates
2022-10-11 12:15:12
  • Multiple Updates
2022-10-11 01:05:11
  • Multiple Updates
2021-05-05 01:10:05
  • Multiple Updates
2021-05-04 12:19:20
  • Multiple Updates
2021-04-22 01:23:04
  • Multiple Updates
2020-05-23 13:16:59
  • Multiple Updates
2020-05-23 01:48:14
  • Multiple Updates
2020-05-23 00:33:02
  • Multiple Updates
2017-08-29 09:23:43
  • Multiple Updates
2016-12-31 09:24:16
  • Multiple Updates
2016-06-28 19:01:54
  • Multiple Updates
2016-04-26 21:34:10
  • Multiple Updates
2015-10-18 17:22:16
  • Multiple Updates
2015-07-28 21:24:09
  • Multiple Updates
2015-06-18 13:27:56
  • Multiple Updates
2014-02-17 11:08:29
  • Multiple Updates
2013-05-10 22:34:14
  • Multiple Updates
2012-11-20 13:22:27
  • Multiple Updates