PT-2010-3184 · Irfanview · Irfanview

Publicado

2010-05-14

·

Atualizado

2018-10-10

·

CVE-2010-1509

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions IrfanView versions prior to 4.27
Description The issue is related to the improper handling of an unspecified integer variable during the processing of PSD images. This can be exploited by remote attackers using a crafted image file, potentially triggering a heap-based buffer overflow due to a sign-extension error. The exploitation can lead to a denial of service, causing the application to crash, or possibly allow the execution of arbitrary code.
Recommendations For versions prior to 4.27, update to version 4.27 or later to resolve the issue.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1509

Produtos afetados

Irfanview