Denial of Service Vulnerability in IrfanView PDF Plugin
CVE-2017-15260

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
11 October 2017

What is CVE-2017-15260?

IrfanView version 4.44 (32bit) with the associated PDF plugin version 4.43 has a vulnerability that allows attackers to create a crafted PDF file that may lead to a denial of service. This flaw is related to improper handling of data, where faulting addresses might influence return values, enabling potential service disruption when the affected PDF is processed.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.