Denial of Service Vulnerability in IrfanView with BabaCAD4Image Plugin
CVE-2017-15755

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
22 October 2017

What is CVE-2017-15755?

A vulnerability in IrfanView version 4.50 for 64-bit systems, specifically related to the BabaCAD4Image plugin version 1.3, allows attackers to exploit crafted .dwg files. This exploitation can lead to a denial of service and potentially unforeseen impacts, disrupting the normal operation of the software. Proper safeguards should be implemented to mitigate such risks, particularly in environments that utilize this software for image processing tasks.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.