Denial of Service Vulnerability in IrfanView PDF Plugin by IrfanView
CVE-2017-15256

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
11 October 2017

What is CVE-2017-15256?

A flaw exists in IrfanView 4.44 (32bit) with PDF plugin 4.43, where specially crafted PDF files can lead to a denial of service attack. This vulnerability arises from improper handling of data when accessing certain memory addresses. Attackers can leverage this flaw to disrupt normal operations by causing the application to crash or behave unexpectedly, potentially allowing for further exploitation.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.