CVE-2017-15260: Buffer Overflow
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address may be used as a return value starting at PDF!xmlParserInputRead+0x0000000000129a59."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15260?
CVE-2017-15260 has been identified as having a denial of service impact due to flaws in handling crafted PDF files.
How do I fix CVE-2017-15260?
To mitigate CVE-2017-15260, users should upgrade to the latest versions of IrfanView and its PDF plugin.
What versions are affected by CVE-2017-15260?
CVE-2017-15260 affects IrfanView version 4.44 (32bit) and its PDF plugin version 4.43.
Can CVE-2017-15260 lead to data exposure?
CVE-2017-15260 is primarily associated with a denial of service; however, it may lead to unspecified impacts, potentially including data exposure.
Is there a workaround for CVE-2017-15260?
Currently, the best approach to avoid CVE-2017-15260 is to refrain from opening untrusted PDF files until the software is updated.