First published: Wed Oct 11 2017(Updated: )
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlGetGlobalState+0x000000000007dfa5."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView IrfanView | =4.44 | |
Irfanview Pdf | =4.43 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15254 has a medium severity since it can cause a denial of service through specially crafted PDF files.
To fix CVE-2017-15254, users should update to the latest version of IrfanView and the PDF plugin.
CVE-2017-15254 affects IrfanView version 4.44 (32bit) and PDF plugin version 4.43.
CVE-2017-15254 can lead to a denial of service or potentially unspecified other impacts upon processing malicious PDF files.
Currently, there are no known workarounds for CVE-2017-15254 other than updating the affected software.