CVE-2017-15256: Buffer Overflow
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlListWalk+0x0000000000019fc8."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15256?
CVE-2017-15256 has a severity level that may lead to a denial of service and potential unspecified impacts.
How do I fix CVE-2017-15256?
To fix CVE-2017-15256, update IrfanView to the latest version and ensure the PDF plugin is also updated.
What versions are affected by CVE-2017-15256?
CVE-2017-15256 affects IrfanView version 4.44 (32-bit) and PDF plugin version 4.43.
What kind of attack does CVE-2017-15256 enable?
CVE-2017-15256 allows attackers to cause a denial of service through crafted PDF files.
Is there any workaround for CVE-2017-15256?
As of now, the best workaround for CVE-2017-15256 is to avoid opening untrusted PDF files in the affected versions of IrfanView.