First published: Sun Oct 22 2017(Updated: )
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at CADIMAGE+0x00000000003e9462."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView | =4.50 | |
IrfanView | =12.0.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15765 has a medium severity rating due to the potential for denial of service attacks.
To fix CVE-2017-15765, update to IrfanView 4.51 or higher, and ensure the CADImage plugin is updated to the latest version.
CVE-2017-15765 enables attackers to cause a denial of service through a crafted .dwg file.
CVE-2017-15765 affects IrfanView 4.50 - 64bit and CADImage plugin version 12.0.0.5.
Exploiting CVE-2017-15765 may lead to denial of service or potentially unspecified other impacts.