CVE-2019-17247: High severity irfanview vulnerability
Published Oct 8, 2019
·Updated
IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEGLS+0x0000000000007da8.
Affected Software
1 affected component
IrfanView IrfanView=4.53
Event History
Oct 8, 2019
CVE Published
via MITRE·11:19 AM
Data Sourced
via MITRE·11:19 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17247?
CVE-2019-17247 has a medium severity rating due to the potential for control over memory addresses leading to arbitrary code execution.
2
How do I fix CVE-2019-17247?
To fix CVE-2019-17247, update IrfanView to the latest version available from the official IrfanView website.
3
What versions of IrfanView are affected by CVE-2019-17247?
IrfanView version 4.53 is the affected version for CVE-2019-17247.
4
What kind of vulnerability is CVE-2019-17247?
CVE-2019-17247 is a memory corruption vulnerability that can allow data from a faulting address to influence subsequent memory writes.
5
Is there any workaround for CVE-2019-17247?
Currently, disabling the use of certain JPEG files until an update is applied can serve as a temporary workaround for CVE-2019-17247.