First published: Wed Apr 11 2007(Updated: )
Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView | =3.99 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1948 has a high severity rating due to the potential for a buffer overflow that could result in arbitrary code execution.
To fix CVE-2007-1948, users should update IrfanView to the latest version that addresses the buffer overflow vulnerabilities.
CVE-2007-1948 specifically affects IrfanView version 3.99.
The potential impacts of CVE-2007-1948 include denial of service and the execution of arbitrary code by attackers.
Yes, CVE-2007-1948 can be exploited by context-dependent attackers using specially crafted BMP images.