CVE-2017-15246: Buffer Overflow
Published Oct 11, 2017
·Updated
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "Read Access Violation on Block Data Move starting at PDF!xmlListWalk+0x000000000001515b."
Affected Software
2 affected components
IrfanView IrfanView=4.44
IrfanView PDF=4.43
Event History
Oct 11, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15246?
CVE-2017-15246 has a high severity rating due to its potential to allow arbitrary code execution or denial of service.
2
How do I fix CVE-2017-15246?
To fix CVE-2017-15246, upgrade to the latest version of IrfanView and ensure the PDF plugin is updated.
3
Which versions are affected by CVE-2017-15246?
CVE-2017-15246 affects IrfanView version 4.44 (32bit) and PDF plugin version 4.43.
4
What type of vulnerability is CVE-2017-15246?
CVE-2017-15246 is a security vulnerability that can lead to arbitrary code execution and denial of service.
5
Can CVE-2017-15246 be exploited remotely?
Yes, CVE-2017-15246 can be exploited remotely through crafted PDF files.