Detect date
?
|
10/11/2017 |
Severity
?
|
High |
Description
|
Multiple serious vulnerabilities have been found in IrfanView 4.44. Malicious users can exploit these vulnerabilities to cause a denial of service or execute arbitrary code. Below is a complete list of vulnerabilities:
Technical details Vulnerability (1) occurs while viewing image in IrfanView or by using its thumbnailing feature. Vulnerabilities (2) are related to:
Vulnerabilities (3) are related to: “User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000a529.” Vulnerability (6) exists because of a User Mode Write AV near NULL. Vulnerabilities (7) are related to: “User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000000f53.” Vulnerabilities (9) are related to: “Read Access Violation on Block Data Move starting at ntdll_77df0000!memcpy+0x0000000000000033.” Vulnerabilities (10) are related to: “Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x000000000011d767.” Vulnerability (11) related to “Data from Faulting Address controls Branch Selection starting at ntdll_77130000!RtlpCoalesceFreeBlocks+0x00000000000004b4.” Vulnerability (12) related to “Data from Faulting Address controls Branch Selection starting at DJVU!GetPlugInInfo+0x000000000001c613.” Vulnerabilities 10-12 affect only 32-bit version of IrfanView. Vulnerability (13) related to: “Data from Faulting Address controls Code Flow starting at PDF!xmlParserInputRead+0x000000000009174a.” Vulnerability (14) related to: “Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at image00000000_00400000+0x00000000000236e4.” NB: Not every vulnerability already has CVSS rating, so cumulative CVSS rating can be not representative. |
Affected products
|
IrfanView version 4.44 |
Solution
|
Update to the latest version |
Original advisories
|
|
Impacts
?
|
ACE [?] DoS [?] |
Related products
|
IrfanView |
CVE-IDS
?
|
CVE-2017-152396.8High
CVE-2017-152406.8High CVE-2017-152416.8High CVE-2017-152426.8High CVE-2017-152436.8High CVE-2017-152446.8High CVE-2017-152456.8High CVE-2017-152466.8High CVE-2017-152476.8High CVE-2017-152486.8High CVE-2017-152496.8High CVE-2017-152506.8High CVE-2017-152516.8High CVE-2017-152526.8High CVE-2017-152536.8High CVE-2017-152546.8High CVE-2017-152556.8High CVE-2017-152566.8High CVE-2017-152576.8High CVE-2017-152586.8High CVE-2017-152596.8High CVE-2017-152606.8High CVE-2017-152616.8High CVE-2017-152626.8High CVE-2017-152636.8High CVE-2017-152646.8High CVE-2017-109246.8High CVE-2017-146934.6Warning CVE-2017-109266.8High CVE-2017-145784.6Warning CVE-2017-83696.8High CVE-2017-83706.8High CVE-2017-87666.8High CVE-2017-95346.8High CVE-2017-95286.8High CVE-2017-95304.4Warning CVE-2017-95316.8High CVE-2017-95326.8High CVE-2017-95336.8High CVE-2017-28136.8High CVE-2017-95356.8High CVE-2017-95366.8High CVE-2017-98736.8High CVE-2017-98746.8High CVE-2017-98756.8High CVE-2017-98766.8High CVE-2017-98776.8High CVE-2017-98786.8High CVE-2017-98796.8High CVE-2017-98806.8High CVE-2017-98816.8High CVE-2017-98826.8High CVE-2017-98836.8High CVE-2017-98846.8High CVE-2017-98856.8High CVE-2017-98866.8High CVE-2017-98876.8High CVE-2017-98886.8High CVE-2017-98896.8High CVE-2017-98906.8High CVE-2017-98916.8High CVE-2017-98926.8High CVE-2017-145394.6Warning CVE-2017-145404.6Warning CVE-2017-107296.8High CVE-2017-107306.8High CVE-2017-107316.8High CVE-2017-107326.8High CVE-2017-107336.8High CVE-2017-107346.8High CVE-2017-107356.8High CVE-2017-109256.8High CVE-2017-99156.8High CVE-2017-99164.6Warning CVE-2017-99174.4Warning CVE-2017-99184.4Warning CVE-2017-99194.4Warning CVE-2017-99204.4Warning CVE-2017-99214.4Warning CVE-2017-99224.4Warning |
Find out the statistics of the vulnerabilities spreading in your region |