CVE-2017-9880: Buffer Overflow
Published Jul 5, 2017
·Updated
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX+0x0000000000007236."
Affected Software
2 affected components
IrfanView IrfanView=4.44
IrfanView FPX=4.46
Event History
Jul 5, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9880?
CVE-2017-9880 has a high severity rating, allowing attackers to execute arbitrary code or cause denial of service.
2
How do I fix CVE-2017-9880?
To fix CVE-2017-9880, update IrfanView to a version above 4.44 and ensure the FPX plugin is updated to the latest version.
3
Which versions of IrfanView are affected by CVE-2017-9880?
CVE-2017-9880 affects IrfanView version 4.44 (32bit) and FPX Plugin version 4.46.
4
What kind of files can exploit CVE-2017-9880?
CVE-2017-9880 can be exploited by using a crafted .fpx file.
5
What type of vulnerabilities does CVE-2017-9880 represent?
CVE-2017-9880 represents a code execution vulnerability stemming from improper handling of file input.