CVE-2017-9885: Buffer Overflow
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX!FPXGetScanDevicePropertyGroup+0x0000000000006a98."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9885?
CVE-2017-9885 has a medium severity rating due to its potential to cause denial of service.
How do I fix CVE-2017-9885?
To fix CVE-2017-9885, upgrade IrfanView to version 4.45 or later, and ensure the FPX Plugin is updated.
What type of attack is associated with CVE-2017-9885?
CVE-2017-9885 is associated with denial of service attacks that can result from opening crafted .fpx files.
Which software versions are affected by CVE-2017-9885?
CVE-2017-9885 affects IrfanView version 4.44 (32bit) and FPX Plugin version 4.46.
Can CVE-2017-9885 lead to other impacts besides denial of service?
Yes, CVE-2017-9885 may potentially lead to unspecified other impacts as well as denial of service.