CVE-2017-15766: Buffer Overflow
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001f0a0."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15766?
CVE-2017-15766 describes a vulnerability in IrfanView that can lead to denial of service or other unspecified impacts.
How do I fix CVE-2017-15766?
To mitigate CVE-2017-15766, update IrfanView to the latest version and ensure that the BabaCAD4Image plugin is also updated.
What products are affected by CVE-2017-15766?
CVE-2017-15766 affects IrfanView version 4.50 - 64bit and the BabaCAD4Image plugin version 1.3.
What type of attack can be executed through CVE-2017-15766?
CVE-2017-15766 allows attackers to execute a denial of service attack using a crafted .dwg file.
Is there a workaround for CVE-2017-15766?
Disabling or uninstalling the BabaCAD4Image plugin may serve as a temporary workaround for CVE-2017-15766.