Code Execution Vulnerability in IrfanView PDF Plugin by Irfan Skiljan
CVE-2017-15249

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
11 October 2017

What is CVE-2017-15249?

The IrfanView software, specifically version 4.44 (32bit) using the PDF plugin version 4.43, is susceptible to a vulnerability that allows attackers to execute arbitrary code or lead to a denial of service. This issue is triggered by the manipulation of specially crafted PDF files, which disrupts normal code flow. Attackers can exploit the vulnerability through carefully designed PDF documents that may corrupt data handling within the software, posing significant risks to users.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.