CVE-1999-1112: Buffer Overflow
Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IrfanView32from your environment.Uninstall IrfanView32 version 3.07 and earlier from affected systems.
- Compensating control
Do not open untrusted Adobe Photoshop (.psd) images with IrfanView. Block or quarantine .psd files at email gateways and file upload points, and restrict user ability to open received .psd files until a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1112?
CVE-1999-1112 is considered a high severity vulnerability due to the potential for attackers to execute arbitrary commands.
How do I fix CVE-1999-1112?
To fix CVE-1999-1112, users should upgrade to IrfanView version 3.08 or later, which addresses this buffer overflow issue.
What types of attacks can exploit CVE-1999-1112?
CVE-1999-1112 can be exploited via crafted Photo Shop image files containing long strings in the header.
Which versions of IrfanView are affected by CVE-1999-1112?
IrfanView versions 3.07 and earlier are affected by CVE-1999-1112.
What are the consequences of exploiting CVE-1999-1112?
Exploiting CVE-1999-1112 can allow attackers to execute arbitrary commands on the target system, potentially leading to data compromise.