CVE-2017-15737: Buffer Overflow
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADIMAGE+0x00000000003d246f."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15737?
CVE-2017-15737 is a vulnerability that can cause a denial of service, indicating a moderate level of severity based on its potential impact.
How do I fix CVE-2017-15737?
To mitigate CVE-2017-15737, users should update to the latest version of IrfanView and the CADImage plugin, ensuring that they are not using vulnerable versions.
What types of attack can CVE-2017-15737 be exploited for?
CVE-2017-15737 can be exploited to cause a denial of service and potentially lead to unspecified other impacts via a crafted .dwg file.
Which versions of IrfanView are affected by CVE-2017-15737?
IrfanView version 4.50 is specifically listed as vulnerable to CVE-2017-15737 when used with CADImage plugin version 12.0.0.5.
Is CVE-2017-15737 a remote or local vulnerability?
CVE-2017-15737 is considered a local vulnerability, as it requires the user to open a maliciously crafted file to trigger the denial of service.