PT-2020-7473 · Irfan Skiljan · Irfanview
Published
2020-01-02
·
Updated
2020-01-14
·
CVE-2013-3944
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
IrfanView versions prior to 4.37
Description:
The issue is a stack-based buffer overflow in the MrSID plugin, which allows remote attackers to execute arbitrary code via an IMAGE tag. This can be exploited by attackers to gain unauthorized access to systems.
Recommendations:
For versions prior to 4.37, update to version 4.37 or later to resolve the issue. As a temporary workaround, consider disabling the MrSID plugin until a patch is available. Restrict access to image files that could potentially exploit this issue to minimize the risk of exploitation.
Fix
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Irfanview