First published: Wed Jul 05 2017(Updated: )
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResGetMappingSize+0x00000000000003cc."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView IrfanView | =4.44 | |
Irfanview Tools | =4.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9921 is classified as a critical vulnerability due to its potential to cause denial of service and execute arbitrary code.
To fix CVE-2017-9921, update IrfanView to version 4.44 or later and ensure the TOOLS Plugin is updated to version 4.50 or later.
IrfanView version 4.44 and the TOOLS Plugin version 4.50 are affected by CVE-2017-9921.
CVE-2017-9921 can be exploited to launch a denial of service attack or to execute arbitrary code.
Yes, CVE-2017-9921 can be triggered by processing a specially crafted file.