Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via a crafted JPEG image, aka DirectShow Memory Corruption Vulnerability.
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Windows_7 | Microsoft | - | - |
Windows_8 | Microsoft | - | - |
Windows_8.1 | Microsoft | - | - |
Windows_server_2003 | Microsoft | - | - |
Windows_server_2008 | Microsoft | - | - |
Windows_server_2008 | Microsoft | r2 | r2 |
Windows_server_2012 | Microsoft | - | - |
Windows_server_2012 | Microsoft | r2 | r2 |
Windows_vista | Microsoft | - | - |
Windows_xp | Microsoft | - | - |
Windows_xp | Microsoft | - | - |