First published: Sun Oct 22 2017(Updated: )
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADIMAGE+0x00000000003d246f."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView | =4.50 | |
IrfanView | =12.0.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15737 is a vulnerability that can cause a denial of service, indicating a moderate level of severity based on its potential impact.
To mitigate CVE-2017-15737, users should update to the latest version of IrfanView and the CADImage plugin, ensuring that they are not using vulnerable versions.
CVE-2017-15737 can be exploited to cause a denial of service and potentially lead to unspecified other impacts via a crafted .dwg file.
IrfanView version 4.50 is specifically listed as vulnerable to CVE-2017-15737 when used with CADImage plugin version 12.0.0.5.
CVE-2017-15737 is considered a local vulnerability, as it requires the user to open a maliciously crafted file to trigger the denial of service.