Heap-based buffer overflow in the FlashPix PlugIn before 4.3.4.0 for IrfanView might allow remote attackers to execute arbitrary code via a .fpx file containing a crafted FlashPix image that is not properly handled during decompression.Referenceshttp://www.securityfocus.com/bid/53009http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=41&Itemid=41http://secunia.com/advisories/48772