First published: Wed Oct 11 2017(Updated: )
IrfanView 4.44 - 32bit with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address may be used as a return value starting at PDF!xmlParserInputRead+0x0000000000040db4."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView | =4.43 | |
IrfanView | =4.44 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15239 has been classified as a vulnerability that can potentially cause a denial of service.
To fix CVE-2017-15239, update IrfanView to version 4.44 or later and ensure that the PDF plugin is updated.
CVE-2017-15239 affects IrfanView version 4.44 and the PDF plugin version 4.43.
CVE-2017-15239 can be exploited remotely when a user opens a malicious PDF file crafted by an attacker.
The impact of CVE-2017-15239 includes potential denial of service or unspecified other impacts due to improper handling of crafted PDF files.