Advisories Blog | G5 Cyber Security

Secunia – IrfanView Formats Integer Overflow

Secunia Research has discovered a vulnerability in IrfanView’s Formats plug-in version 4.22, which can be exploited by malicious people to compromise a user’s system. The vulnerability is caused due to an integer overflow when processing XPM files with certain dimensions. This can be exploited to cause a heap-based buffer overflow by e.g. tricking a user into opening a specially crafted XPM file.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/76425/secunia-irfanviewxpm.txt

Source: https://packetstormsecurity.com/files/76425/Secunia-IrfanView-Formats-Integer-Overflow.html

Exit mobile version