CVE-2017-9536: Buffer Overflow
Published Jul 5, 2017
·Updated
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at FPX!FPXGetScanDevicePropertyGroup+0x00000000000014eb."
Affected Software
2 affected components
IrfanView IrfanView=4.44
IrfanView FPX=4.46
Event History
Jul 5, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9536?
CVE-2017-9536 has a high severity rating due to the ability it gives attackers to execute arbitrary code.
2
How do I fix CVE-2017-9536?
To fix CVE-2017-9536, upgrade to a version of IrfanView that does not include the vulnerable FPX plugin.
3
What are the affected versions in CVE-2017-9536?
CVE-2017-9536 affects IrfanView version 4.44 and FPX Plugin version 4.46.
4
Can CVE-2017-9536 cause a denial of service?
Yes, CVE-2017-9536 can cause a denial of service if an attacker exploits the vulnerability with a crafted .fpx file.
5
Who is vulnerable to CVE-2017-9536?
Users of IrfanView 4.44 with the FPX Plugin 4.46 are vulnerable to CVE-2017-9536.