CVE-2017-9889: Buffer Overflow
Published Jul 5, 2017
·Updated
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at FPX!FPXGetScanDevicePropertyGroup+0x0000000000003714."
Affected Software
2 affected components
IrfanView IrfanView=4.44
IrfanView FPX=4.46
Event History
Jul 5, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9889?
The severity of CVE-2017-9889 is classified as potentially high due to the risk of denial of service attacks.
2
How do I fix CVE-2017-9889?
To fix CVE-2017-9889, users should update IrfanView and the FPX plugin to the latest versions available.
3
What type of attack does CVE-2017-9889 enable?
CVE-2017-9889 enables attackers to carry out denial of service attacks via crafted .fpx files.
4
Which versions of IrfanView are affected by CVE-2017-9889?
CVE-2017-9889 affects IrfanView version 4.44 (32bit) specifically.
5
What is the nature of the vulnerability in CVE-2017-9889?
CVE-2017-9889 involves a Read Access Violation related to the FPX plugin when processing certain .fpx files.