First published: Thu Apr 09 2009(Updated: )
Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView | <=4.22 | |
IrfanView | =4.00 | |
IrfanView | =4.10 | |
IrfanView | =4.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0197 is classified as a high severity vulnerability due to its potential for remote code execution and denial of service.
To fix CVE-2009-0197, upgrade to IrfanView version 4.23 or later, which addresses the integer overflow issue.
CVE-2009-0197 can be exploited by attackers using large XPM files that trigger heap-based buffer overflows.
CVE-2009-0197 affects IrfanView formats plugin versions up to 4.22 and specifically versions 4.00, 4.10, and 4.20.
Exploitation of CVE-2009-0197 can lead to arbitrary code execution or application crashes, resulting in denial of service.