CVE-2013-6932: Buffer Overflow
Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6932?
CVE-2013-6932 is classified as a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2013-6932?
To fix CVE-2013-6932, upgrade IrfanView to version 4.37 or later.
What versions of IrfanView are affected by CVE-2013-6932?
CVE-2013-6932 affects IrfanView versions up to 4.36, including 4.00, 4.10, 4.20, 4.23, 4.25, 4.27, 4.28, 4.30, 4.32, 4.33, and 4.35.
What feature in IrfanView causes CVE-2013-6932?
CVE-2013-6932 is triggered by a buffer overflow in the Thumbnail tooltips feature when handling multibyte-character directory names.
Can CVE-2013-6932 be exploited without user interaction?
Exploitation of CVE-2013-6932 requires user interaction, as it necessitates opening a specially crafted file.