PT-2020-7473 · Irfan Skiljan · Irfanview

Published

2020-01-02

·

Updated

2020-01-14

·

CVE-2013-3944

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: IrfanView versions prior to 4.37
Description: The issue is a stack-based buffer overflow in the MrSID plugin, which allows remote attackers to execute arbitrary code via an IMAGE tag. This can be exploited by attackers to gain unauthorized access to systems.
Recommendations: For versions prior to 4.37, update to version 4.37 or later to resolve the issue. As a temporary workaround, consider disabling the MrSID plugin until a patch is available. Restrict access to image files that could potentially exploit this issue to minimize the risk of exploitation.

Fix

RCE

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3944

Affected Products

Irfanview