Arbitrary Code Execution and Denial of Service in IrfanView with BabaCAD4Image Plugin
CVE-2017-15763
7.8HIGH
What is CVE-2017-15763?
IrfanView version 4.50 - 64bit, when used with BabaCAD4Image plugin version 1.3, is susceptible to a vulnerability that allows attackers to manipulate specially crafted .dwg files. This manipulation can lead to arbitrary code execution or denial of service, resulting in a compromised state for users. The issue arises due to how the application handles data from a faulting address, subsequently affecting write operations. Users are encouraged to upgrade their software and apply security measures to mitigate the risks associated with this vulnerability.
