vendor:
IrfanView
by:
BraniX
N/A
CVSS
MEDIUM
Denial of Service
CWE
Product Name: IrfanView
Affected Version From: IrfanView 4.27
Affected Version To: IrfanView 4.27
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3 Home Edition
2010
IrfanView JPEG2000 DoS
The vulnerability is caused by an integer division by zero in the JPEG2000.dll module of IrfanView 4.27. By providing a specially crafted JP2 file, an attacker can trigger this vulnerability and cause a denial of service condition.
Mitigation:
Update to the latest version of IrfanView or use an alternative software for opening JPEG2000 files.