CVE-2017-9888: Buffer Overflow
Published Jul 5, 2017
·Updated
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at FPX!FPXGetScanDevicePropertyGroup+0x00000000000031a0."
Affected Software
2 affected components
IrfanView IrfanView=4.44
IrfanView FPX=4.46
Event History
Jul 5, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9888?
CVE-2017-9888 is classified as a denial of service vulnerability that can lead to application crashes.
2
How do I fix CVE-2017-9888?
To fix CVE-2017-9888, update to the latest version of IrfanView and its FPX plugin.
3
What software is affected by CVE-2017-9888?
CVE-2017-9888 affects IrfanView version 4.44 and FPX Plugin version 4.46.
4
What type of attack is possible with CVE-2017-9888?
CVE-2017-9888 allows attackers to cause denial of service through crafted .fpx files.
5
Can CVE-2017-9888 lead to data breaches?
CVE-2017-9888 is not reported to cause data breaches, but it can disrupt application availability.