CVE-2023-24304: Input Validation
Published Mar 28, 2023
·Updated
Improper input validation in the PDF.dll plugin of IrfanView v4.60 allows attackers to execute arbitrary code via opening a crafted PDF file.
Affected Software
1 affected component
IrfanView IrfanView=4.60
Event History
Mar 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-24304?
CVE-2023-24304 is a vulnerability in the PDF.dll plugin of IrfanView v4.60 that allows attackers to execute arbitrary code by opening a crafted PDF file.
2
What is the severity of CVE-2023-24304?
The severity of CVE-2023-24304 is high (7.8).
3
How does CVE-2023-24304 affect IrfanView?
CVE-2023-24304 affects IrfanView v4.60 through the PDF.dll plugin.
4
How can an attacker exploit CVE-2023-24304?
An attacker can exploit CVE-2023-24304 by opening a specially crafted PDF file.
5
Is there a fix available for CVE-2023-24304?
Yes, upgrading to a version of IrfanView that is not affected by the vulnerability is recommended to fix CVE-2023-24304.