Denial of Service Vulnerability in IrfanView with CADImage Plugin
CVE-2017-15745

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
22 October 2017

What is CVE-2017-15745?

IrfanView version 4.50 for 64-bit systems, when used with the CADImage plugin version 12.0.0.5, is susceptible to a Denial of Service attack. Attackers can exploit this vulnerability by crafting malicious .dwg files, leading to possible system instability or interruptions. The issue resides in how data from Faulting Address influences Branch Selection, indicating a flaw in the processing of certain file types that, when leveraged, could compromise the application's availability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.