Denial of Service Vulnerability in IrfanView with PDF Plugin
CVE-2017-15254

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
11 October 2017

What is CVE-2017-15254?

A vulnerability has been identified in IrfanView version 4.44 (32bit) coupled with the PDF plugin version 4.43 that allows attackers to initiate a denial of service. This occurs through the manipulation of a specially crafted .pdf file, which can lead to an access violation. The specific code path affected relates to the PDF parsing mechanism. It is critical for users of this software combination to be aware of this flaw to mitigate potential data access issues or service outages.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.