Arbitrary Code Execution Vulnerability in IrfanView with BabaCAD4Image Plugin
CVE-2017-15758
7.8HIGH
What is CVE-2017-15758?
The IrfanView image viewer, specifically version 4.50 for 64-bit systems with the BabaCAD4Image plugin (version 1.3), contains a vulnerability that can be exploited by attackers. This flaw allows for the execution of arbitrary code or the triggering of a denial of service condition when a specially crafted .dwg file is processed. The issue arises due to improper handling of data from a faulting address, which can lead to unintended execution paths. It is crucial for users to be aware of this vulnerability and implement necessary updates to mitigate potential risks.
