First published: Fri May 14 2010(Updated: )
Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView | <=4.25 | |
IrfanView | =1.70 | |
IrfanView | =1.75 | |
IrfanView | =1.80 | |
IrfanView | =1.85 | |
IrfanView | =1.90 | |
IrfanView | =1.95 | |
IrfanView | =1.97 | |
IrfanView | =1.98 | |
IrfanView | =1.98a | |
IrfanView | =1.99 | |
IrfanView | =2.00 | |
IrfanView | =2.05 | |
IrfanView | =2.07 | |
IrfanView | =2.10 | |
IrfanView | =2.12 | |
IrfanView | =2.15 | |
IrfanView | =2.17 | |
IrfanView | =2.18 | |
IrfanView | =2.20 | |
IrfanView | =2.22 | |
IrfanView | =2.25 | |
IrfanView | =2.27 | |
IrfanView | =2.30 | |
IrfanView | =2.32 | |
IrfanView | =2.35 | |
IrfanView | =2.37 | |
IrfanView | =2.40 | |
IrfanView | =2.50 | |
IrfanView | =2.52 | |
IrfanView | =2.55 | |
IrfanView | =2.60 | |
IrfanView | =2.62 | |
IrfanView | =2.63 | |
IrfanView | =2.65 | |
IrfanView | =2.66 | |
IrfanView | =2.68 | |
IrfanView | =2.80 | |
IrfanView | =2.82 | |
IrfanView | =2.83 | |
IrfanView | =2.85 | |
IrfanView | =2.90 | |
IrfanView | =2.92 | |
IrfanView | =2.95 | |
IrfanView | =2.97 | |
IrfanView | =2.98 | |
IrfanView | =3.00 | |
IrfanView | =3.02 | |
IrfanView | =3.05 | |
IrfanView | =3.07 | |
IrfanView | =3.10 | |
IrfanView | =3.12 | |
IrfanView | =3.15 | |
IrfanView | =3.17 | |
IrfanView | =3.20 | |
IrfanView | =3.21 | |
IrfanView | =3.25 | |
IrfanView | =3.30 | |
IrfanView | =3.33 | |
IrfanView | =3.35 | |
IrfanView | =3.36 | |
IrfanView | =3.50 | |
IrfanView | =3.51 | |
IrfanView | =3.60 | |
IrfanView | =3.61 | |
IrfanView | =3.70 | |
IrfanView | =3.75 | |
IrfanView | =3.80 | |
IrfanView | =3.85 | |
IrfanView | =3.90 | |
IrfanView | =3.91 | |
IrfanView | =3.92 | |
IrfanView | =3.95 | |
IrfanView | =3.97 | |
IrfanView | =3.98 | |
IrfanView | =3.99 | |
IrfanView | =4.00 | |
IrfanView | =4.10 | |
IrfanView | =4.20 | |
IrfanView | =4.22 | |
IrfanView | =4.23 | |
<=4.25 | ||
=1.70 | ||
=1.75 | ||
=1.80 | ||
=1.85 | ||
=1.90 | ||
=1.95 | ||
=1.97 | ||
=1.98 | ||
=1.98a | ||
=1.99 | ||
=2.00 | ||
=2.05 | ||
=2.07 | ||
=2.10 | ||
=2.12 | ||
=2.15 | ||
=2.17 | ||
=2.18 | ||
=2.20 | ||
=2.22 | ||
=2.25 | ||
=2.27 | ||
=2.30 | ||
=2.32 | ||
=2.35 | ||
=2.37 | ||
=2.40 | ||
=2.50 | ||
=2.52 | ||
=2.55 | ||
=2.60 | ||
=2.62 | ||
=2.63 | ||
=2.65 | ||
=2.66 | ||
=2.68 | ||
=2.80 | ||
=2.82 | ||
=2.83 | ||
=2.85 | ||
=2.90 | ||
=2.92 | ||
=2.95 | ||
=2.97 | ||
=2.98 | ||
=3.00 | ||
=3.02 | ||
=3.05 | ||
=3.07 | ||
=3.10 | ||
=3.12 | ||
=3.15 | ||
=3.17 | ||
=3.20 | ||
=3.21 | ||
=3.25 | ||
=3.30 | ||
=3.33 | ||
=3.35 | ||
=3.36 | ||
=3.50 | ||
=3.51 | ||
=3.60 | ||
=3.61 | ||
=3.70 | ||
=3.75 | ||
=3.80 | ||
=3.85 | ||
=3.90 | ||
=3.91 | ||
=3.92 | ||
=3.95 | ||
=3.97 | ||
=3.98 | ||
=3.99 | ||
=4.00 | ||
=4.10 | ||
=4.20 | ||
=4.22 | ||
=4.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1510 is classified as a medium severity vulnerability due to its potential to cause application crashes or arbitrary code execution.
To fix CVE-2010-1510, update IrfanView to version 4.27 or later, which addresses the buffer overflow issue.
CVE-2010-1510 can be exploited by remote attackers through specially crafted PSD images that utilize RLE compression.
CVE-2010-1510 affects IrfanView versions before 4.27, including versions as low as 1.70.
Exploiting CVE-2010-1510 can lead to denial of service by crashing the application or potentially allowing the execution of arbitrary code.