Denial of Service and Arbitrary Code Execution Vulnerability in IrfanView by Irfan Skiljan
CVE-2017-9918

7.8HIGH

Key Information:

Vendor

Irfanview

Vendor
CVE Published:
5 July 2017

What is CVE-2017-9918?

IrfanView version 4.44 (32bit), when used with the TOOLS Plugin 4.50, potentially allows attackers to initiate a denial of service or execute arbitrary code. This vulnerability arises from handling crafted files, which can control branch selection through faulty memory access. Proper precautions and updates should be applied to mitigate associated risks.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.