Описание
Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.
Ссылки
- Vendor Advisory
- Exploit
- Vendor Advisory
- Exploit
Уязвимые конфигурации
Конфигурация 1Версия до 4.30 (включая)
Одно из
cpe:2.3:a:irfanview:irfanview:*:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:3.90:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:3.91:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:3.92:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:3.95:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:3.97:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:3.98:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:3.99:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.00:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.10:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.20:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.23:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.25:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.27:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.28:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.48547
Средний
4.3 Medium
CVSS2
Дефекты
CWE-119
Связанные уязвимости
github
больше 3 лет назад
Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.
EPSS
Процентиль: 98%
0.48547
Средний
4.3 Medium
CVSS2
Дефекты
CWE-119