CVE-2009-0197: Buffer Overflow
Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0197?
CVE-2009-0197 is classified as a high severity vulnerability due to its potential for remote code execution and denial of service.
How do I fix CVE-2009-0197?
To fix CVE-2009-0197, upgrade to IrfanView version 4.23 or later, which addresses the integer overflow issue.
What types of attacks can exploit CVE-2009-0197?
CVE-2009-0197 can be exploited by attackers using large XPM files that trigger heap-based buffer overflows.
Which versions of IrfanView are affected by CVE-2009-0197?
CVE-2009-0197 affects IrfanView formats plugin versions up to 4.22 and specifically versions 4.00, 4.10, and 4.20.
What are the potential consequences of CVE-2009-0197?
Exploitation of CVE-2009-0197 can lead to arbitrary code execution or application crashes, resulting in denial of service.