CVE-2009-2118: Code Injection
Published Jun 18, 2009
·Updated
Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.
Affected Software
1 affected component
IrfanView IrfanView=4.23
Remediation
Patch Available
Patch Available
Event History
Jun 18, 2009
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2118?
CVE-2009-2118 is considered critical due to the potential for arbitrary code execution.
2
How do I fix CVE-2009-2118?
To fix CVE-2009-2118, update IrfanView to the latest version that addresses this vulnerability.
3
What versions of IrfanView are affected by CVE-2009-2118?
CVE-2009-2118 specifically affects IrfanView version 4.23.
4
What type of attack can CVE-2009-2118 facilitate?
CVE-2009-2118 can facilitate remote code execution attacks through crafted TIFF images.
5
Is there a workaround for CVE-2009-2118?
Disabling the resampling or screen fitting options in IrfanView may serve as a temporary workaround for CVE-2009-2118.