Skip to main content

IrfanView ANI File Processing Integer Overflow Vulnerability

Last Update Date: 8 Jul 2013 09:53 Release Date: 8 Jul 2013 3308 Views

RISK: High Risk

TYPE: Clients - Graphics & Design

TYPE: Graphics & Design

A vulnerability has been identified in IrfanView, which can be exploited by malicious people to compromise a user's system.
 

The vulnerability is caused due to an integer overflow error when parsing ANI images and can be exploited to cause a heap-based buffer overflow.


Impact

  • Remote Code Execution

System / Technologies affected

  • IrfanView 4.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 4.36.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link