PT-2007-3293 · Irfanview · Irfanview

Published

2007-04-10

·

Updated

2018-10-16

·

CVE-2007-1948

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IrfanView version 3.99
Description The issue allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the xoffset or yoffset RLE command, or large non-RLE encoded blocks in a crafted BMP image.
Recommendations For IrfanView version 3.99, consider avoiding the use of RLE commands or non-RLE encoded blocks in BMP images until a patch is available. As a temporary workaround, restrict the opening of crafted BMP images to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1948

Affected Products

Irfanview