First published: Tue Oct 08 2019(Updated: )
IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x0000000000007da8.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IrfanView | =4.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17247 has a medium severity rating due to the potential for control over memory addresses leading to arbitrary code execution.
To fix CVE-2019-17247, update IrfanView to the latest version available from the official IrfanView website.
IrfanView version 4.53 is the affected version for CVE-2019-17247.
CVE-2019-17247 is a memory corruption vulnerability that can allow data from a faulting address to influence subsequent memory writes.
Currently, disabling the use of certain JPEG files until an update is applied can serve as a temporary workaround for CVE-2019-17247.