First published: Fri May 14 2010(Updated: )
IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a "sign-extension error."
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView | =1.70 | |
IrfanView | =2.50 | |
IrfanView | =3.15 | |
IrfanView | =1.80 | |
IrfanView | =4.20 | |
IrfanView | =2.63 | |
IrfanView | =2.15 | |
IrfanView | =3.35 | |
IrfanView | =2.18 | |
IrfanView | =3.90 | |
IrfanView | =3.20 | |
IrfanView | =3.99 | |
IrfanView | =2.65 | |
IrfanView | =2.12 | |
IrfanView | =3.02 | |
IrfanView | =2.10 | |
IrfanView | =3.07 | |
IrfanView | =1.97 | |
IrfanView | =3.50 | |
IrfanView | =2.37 | |
IrfanView | =2.60 | |
IrfanView | =2.27 | |
IrfanView | =2.20 | |
IrfanView | =3.30 | |
IrfanView | =2.25 | |
IrfanView | =3.61 | |
IrfanView | =2.40 | |
IrfanView | =1.75 | |
IrfanView | =3.33 | |
IrfanView | =2.30 | |
IrfanView | =2.85 | |
IrfanView | =2.07 | |
IrfanView | =2.66 | |
IrfanView | =3.12 | |
IrfanView | =3.85 | |
IrfanView | =2.80 | |
IrfanView | =2.98 | |
IrfanView | =3.00 | |
IrfanView | =2.90 | |
IrfanView | =3.97 | |
IrfanView | =2.68 | |
IrfanView | =4.23 | |
IrfanView | =3.70 | |
IrfanView | =3.17 | |
IrfanView | =2.05 | |
IrfanView | <=4.25 | |
IrfanView | =2.32 | |
IrfanView | =2.35 | |
IrfanView | =3.51 | |
IrfanView | =3.25 | |
IrfanView | =1.90 | |
IrfanView | =3.75 | |
IrfanView | =1.85 | |
IrfanView | =3.05 | |
IrfanView | =2.83 | |
IrfanView | =4.00 | |
IrfanView | =2.97 | |
IrfanView | =3.21 | |
IrfanView | =3.91 | |
IrfanView | =1.95 | |
IrfanView | =2.82 | |
IrfanView | =1.98a | |
IrfanView | =3.36 | |
IrfanView | =4.22 | |
IrfanView | =3.92 | |
IrfanView | =2.95 | |
IrfanView | =4.10 | |
IrfanView | =2.22 | |
IrfanView | =2.62 | |
IrfanView | =1.99 | |
IrfanView | =3.60 | |
IrfanView | =3.10 | |
IrfanView | =2.00 | |
IrfanView | =3.95 | |
IrfanView | =2.55 | |
IrfanView | =2.52 | |
IrfanView | =3.80 | |
IrfanView | =2.17 | |
IrfanView | =3.98 | |
IrfanView | =2.92 | |
IrfanView | =1.98 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1509 has been classified as a moderate severity vulnerability due to its potential for denial of service and possible arbitrary code execution.
To mitigate CVE-2010-1509, users should upgrade to IrfanView version 4.27 or later, which addresses the vulnerability.
CVE-2010-1509 can be exploited by attackers using crafted PSD image files to cause application crashes or execute arbitrary code.
IrfanView versions prior to 4.27, including versions 1.70 to 4.20, are affected by CVE-2010-1509.
CVE-2010-1509 is a heap-based buffer overflow vulnerability that occurs during the processing of PSD images.