First published: Wed Jul 05 2017(Updated: )
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResCompareResourceNames+0x0000000000000087."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView IrfanView | =4.44 | |
Irfanview Tools | =4.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9919 has a medium severity rating due to its potential to cause denial of service or execute arbitrary code.
To mitigate CVE-2017-9919, update IrfanView to version 4.45 or later and the TOOLS Plugin to version 4.51 or later.
CVE-2017-9919 can lead to system crashes or allow attackers to execute malicious commands on the affected systems.
CVE-2017-9919 affects IrfanView version 4.44 (32bit) and the TOOLS Plugin version 4.50.
CVE-2017-9919 can facilitate denial of service attacks and remote code execution if a crafted file is opened.