PT-2010-3184 · Irfanview · Irfanview

Published

2010-05-14

·

Updated

2018-10-10

·

CVE-2010-1509

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions IrfanView versions prior to 4.27
Description The issue is related to the improper handling of an unspecified integer variable during the processing of PSD images. This can be exploited by remote attackers using a crafted image file, potentially triggering a heap-based buffer overflow due to a sign-extension error. The exploitation can lead to a denial of service, causing the application to crash, or possibly allow the execution of arbitrary code.
Recommendations For versions prior to 4.27, update to version 4.27 or later to resolve the issue.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1509

Affected Products

Irfanview