CVE-2017-9886: Buffer Overflow
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll77df0000!RtlpLowFragHeapFree+0x000000000000001f."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9886?
CVE-2017-9886 has been classified as a medium severity vulnerability, potentially leading to denial of service.
How do I fix CVE-2017-9886?
To fix CVE-2017-9886, you should update IrfanView to version 4.45 or later, which addresses the vulnerability.
What versions of IrfanView are affected by CVE-2017-9886?
CVE-2017-9886 affects IrfanView version 4.44 (32bit) and FPX Plugin version 4.46.
What type of impact can CVE-2017-9886 cause?
CVE-2017-9886 can cause a denial of service or potentially have unspecified other impacts via a crafted .fpx file.
Is CVE-2017-9886 specific to a particular file type?
Yes, CVE-2017-9886 specifically affects files with the .fpx extension when opened in the vulnerable versions of IrfanView.