CVE-2010-1509: Buffer Overflow
IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a "sign-extension error."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1509?
CVE-2010-1509 has been classified as a moderate severity vulnerability due to its potential for denial of service and possible arbitrary code execution.
How do I fix CVE-2010-1509?
To mitigate CVE-2010-1509, users should upgrade to IrfanView version 4.27 or later, which addresses the vulnerability.
What types of attacks can occur due to CVE-2010-1509?
CVE-2010-1509 can be exploited by attackers using crafted PSD image files to cause application crashes or execute arbitrary code.
Which versions of IrfanView are affected by CVE-2010-1509?
IrfanView versions prior to 4.27, including versions 1.70 to 4.20, are affected by CVE-2010-1509.
What kind of vulnerability is CVE-2010-1509?
CVE-2010-1509 is a heap-based buffer overflow vulnerability that occurs during the processing of PSD images.