CVE-2017-15249: Buffer Overflow
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlGetGlobalState+0x00000000000668d6."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15249?
CVE-2017-15249 is considered critical as it allows attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2017-15249?
To mitigate CVE-2017-15249, users should upgrade IrfanView to version 4.45 or above and ensure that the PDF plugin is updated to the latest version.
Which versions are affected by CVE-2017-15249?
CVE-2017-15249 affects IrfanView version 4.44 (32bit) and the PDF plugin version 4.43.
What type of attacks can exploit CVE-2017-15249?
Attackers can exploit CVE-2017-15249 by using a crafted .pdf file to execute arbitrary code on the victim's system.
Is CVE-2017-15249 specific to any operating system?
CVE-2017-15249 is primarily associated with the Windows operating system where IrfanView is commonly used.