CVE-2021-29365: Medium severity irfanview vulnerability
Published Sep 28, 2021
·Updated
Irfanview 4.57 is affected by an infinite loop when processing a crafted BMP file in the EFFECTS!AutoCropW component. This can cause a denial of service (DOS).
Affected Software
1 affected component
IrfanView IrfanView=4.57
Event History
Sep 28, 2021
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-29365?
CVE-2021-29365 is classified as a denial of service vulnerability that can disrupt the application's normal functioning.
2
How do I fix CVE-2021-29365?
To fix CVE-2021-29365, update IrfanView to the latest version available, which addresses this vulnerability.
3
What does CVE-2021-29365 affect?
CVE-2021-29365 affects IrfanView version 4.57 specifically when processing a crafted BMP file.
4
Can CVE-2021-29365 be exploited remotely?
Yes, CVE-2021-29365 can potentially be exploited remotely if a user opens a malicious BMP file.
5
What component is involved in CVE-2021-29365?
The vulnerability in CVE-2021-29365 is associated with the EFFECTS!AutoCrop_W component in IrfanView.