PT-2007-3293 · Irfanview · Irfanview
Published
2007-04-10
·
Updated
2018-10-16
·
CVE-2007-1948
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IrfanView version 3.99
Description
The issue allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the
xoffset or yoffset RLE command, or large non-RLE encoded blocks in a crafted BMP image.Recommendations
For IrfanView version 3.99, consider avoiding the use of RLE commands or non-RLE encoded blocks in BMP images until a patch is available. As a temporary workaround, restrict the opening of crafted BMP images to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Irfanview