CVE-2017-15262: Buffer Overflow
Published Oct 11, 2017
·Updated
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlParserInputRead+0x0000000000048d0c."
Affected Software
2 affected components
IrfanView PDF=4.43
IrfanView IrfanView=4.44
Event History
Oct 11, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15262?
CVE-2017-15262 has a critical severity rating due to its potential for arbitrary code execution.
2
How do I fix CVE-2017-15262?
To fix CVE-2017-15262, upgrade to the latest version of IrfanView and its PDF plugin.
3
What versions are affected by CVE-2017-15262?
CVE-2017-15262 affects IrfanView version 4.44 (32bit) and PDF plugin version 4.43.
4
What types of attacks are possible with CVE-2017-15262?
CVE-2017-15262 can allow attackers to execute arbitrary code or cause a denial of service through crafted PDF files.
5
Is CVE-2017-15262 specific to certain file types?
Yes, CVE-2017-15262 is specifically triggered by maliciously crafted PDF files.