Skip to main content

IrfanView FlashPix PlugIn FPX Processing Integer Overflow Vulnerability

Last Update Date: 31 May 2013 16:40 Release Date: 31 May 2013 3507 Views

RISK: High Risk

TYPE: Clients - Graphics & Design

TYPE: Graphics & Design

A vulnerability has been identified in the FlashPix PlugIn for IrfanView, which can be exploited by malicious people to compromise a user's system.  The vulnerability is caused due to an integer overflow error within the Fpx.dll module when processing sections of Summary Information Property Set, which can be exploited to cause a heap-based buffer overflow. Successful exploitation may allow execution of arbitrary code.


Impact

  • Remote Code Execution

System / Technologies affected

  • IrfanView FlashPix PlugIn 4.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 4.35

Vulnerability Identifier


Source


Related Link