Denial of Service Vulnerability in IrfanView PDF Plugin
CVE-2017-15261

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
11 October 2017

What is CVE-2017-15261?

A vulnerability in IrfanView with the PDF plugin version 4.43 allows attackers to exploit crafted PDF files, potentially leading to denial of service or other unspecified consequences. This issue is linked to a stack corruption problem initiated by the PDF!xmlGetGlobalState function, which can be manipulated through specially crafted inputs.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.