CVE-2011-5233: Buffer Overflow
Published Oct 25, 2012
·Updated
Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.
Affected Software
15 affected components
IrfanView IrfanView<=4.30
IrfanView IrfanView=3.90
IrfanView IrfanView=3.91
IrfanView IrfanView=3.92
IrfanView IrfanView=3.95
IrfanView IrfanView=3.97
IrfanView IrfanView=3.98
IrfanView IrfanView=3.99
IrfanView IrfanView=4.00
IrfanView IrfanView=4.10
IrfanView IrfanView=4.20
IrfanView IrfanView=4.23
IrfanView IrfanView=4.25
IrfanView IrfanView=4.27
IrfanView IrfanView=4.28
Event History
Oct 25, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5233?
CVE-2011-5233 is classified as a high severity vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2011-5233?
To fix CVE-2011-5233, users should update IrfanView to version 4.32 or later.
3
What type of vulnerability is CVE-2011-5233?
CVE-2011-5233 is a heap-based buffer overflow vulnerability.
4
Which versions of IrfanView are affected by CVE-2011-5233?
All versions of IrfanView prior to 4.32, including versions 3.90 to 4.28, are affected by CVE-2011-5233.
5
Can CVE-2011-5233 be exploited through image files?
Yes, CVE-2011-5233 can be exploited using specially crafted TIFF image files.