CVE-2008-0493: Buffer Overflow
Published Jan 30, 2008
·Updated
fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOTE: some of these details are obtained from third party information.
Affected Software
1 affected component
IrfanView IrfanView=4.10
Event History
Jan 30, 2008
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0493?
CVE-2008-0493 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2008-0493?
To fix CVE-2008-0493, update IrfanView to the latest version that addresses this vulnerability.
3
What causes the vulnerability CVE-2008-0493?
CVE-2008-0493 is caused by heap corruption triggered by processing a crafted FlashPix (.FPX) file.
4
What software is affected by CVE-2008-0493?
CVE-2008-0493 affects IrfanView version 4.10 and the FlashPix plugin fpx.dll 3.9.8.0.
5
Can CVE-2008-0493 be exploited remotely?
Yes, CVE-2008-0493 can be exploited remotely by attackers through malicious FlashPix files.