Denial of Service Vulnerability in IrfanView PDF Plugin by Irfan Skiljan
CVE-2017-15247

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
11 October 2017

What is CVE-2017-15247?

A vulnerability exists in IrfanView version 4.44 (32bit) combined with PDF plugin version 4.43, where attackers can exploit a crafted PDF file to trigger a denial of service. The issue is linked to improper handling of data from faulting addresses, leading to potential disruption in the application's operation. This flaw could allow malicious actors to impact users by causing unexpected behavior or crashes when the affected versions process specially crafted PDF documents.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.