Skip to main content

IrfanView Multiple Vulnerabilities

Last Update Date: 21 Dec 2011 10:44 Release Date: 21 Dec 2011 4576 Views

RISK: Medium Risk

TYPE: Clients - Graphics & Design

TYPE: Graphics & Design

Multiple vulnerabilities have been identified in IrfanView, which can be exploited by malicious people to compromise a user's system.

  1. Due to an error when processing TIFF images with certain "Rows Per Strip" and "Samples Per Pixel" values, which can be exploited to cause a heap-based buffer overflow by tricking a user into opening a specially crafted TIFF image file.
  2. Due to the use of a vulnerable version of the libfpx library.

Impact

  • Remote Code Execution

System / Technologies affected

  • IrfanView 4.x
  • IrfanView FlashPix PlugIn 4.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 4.32.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link