PT-2024-23719 · Irfanview · Irfanview
Leeho
+2
·
Published
2024-10-21
·
Updated
2024-10-23
·
CVE-2024-31007
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
IrfanView 32bit version 4.66
Description
A Buffer Overflow issue allows a local attacker to cause a denial of service via a crafted file, affecting the IrfanView 32bit component with the plugin formats.dll.
Recommendations
For IrfanView 32bit version 4.66, consider disabling the formats.dll plugin as a temporary workaround until a patch is available. Restrict access to potentially crafted files to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Irfanview