Denial of Service Vulnerability in IrfanView 4.50 with BabaCAD4Image Plugin
CVE-2017-15753

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
22 October 2017

What is CVE-2017-15753?

A security vulnerability in IrfanView version 4.50 - 64bit, specifically within the BabaCAD4Image plugin version 1.3, permits attackers to execute a denial of service. This may be realized through a specially crafted .dwg file that manipulates memory management, leading to unpredictable behavior or crashes. It is crucial for users and administrators to stay vigilant and consider applying patches or updates to mitigate potential risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.