CVE-2017-9890: Buffer Overflow
Published Jul 5, 2017
·Updated
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at FPX+0x000000000000153a."
Affected Software
2 affected components
IrfanView IrfanView=4.44
IrfanView FPX=4.46
Event History
Jul 5, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9890?
The severity of CVE-2017-9890 is classified as high due to its potential to cause a denial of service.
2
How do I fix CVE-2017-9890?
To fix CVE-2017-9890, update IrfanView to version 4.45 or later or ensure the FPX plugin is updated to a patched version.
3
Which versions are affected by CVE-2017-9890?
CVE-2017-9890 affects IrfanView version 4.44 and the FPX plugin version 4.46.
4
What type of attack does CVE-2017-9890 facilitate?
CVE-2017-9890 facilitates a denial of service attack via a crafted .fpx file.
5
What specific issue does CVE-2017-9890 represent?
CVE-2017-9890 represents a Read Access Violation in the FPX plugin causing the application to crash.