Denial of Service Vulnerability in IrfanView with PDF Plugin
CVE-2017-15241

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
11 October 2017

What is CVE-2017-15241?

A vulnerability in IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to trigger a denial of service by utilizing a specially crafted PDF file. This exploit is connected to improper data handling during PDF processing, specifically in 'Data from Faulting Address', which affects the branch selection routine of the application. Users of affected versions should upgrade to mitigate the risk of potential service disruptions.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.