vendor:
IrfanView
by:
Marsu
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: IrfanView
Affected Version From: 3.99
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:irfanview:irfanview:3.99
Platforms Tested: Windows XP SP2 FR
IrfanView 3.99 .ANI File Buffer Overflow
IrfanView is vulnerable to a buffer overflow when opening a crafted .ani file. The overflow occurs while it is creating a snapshot of the file. This exploit launches calc.exe.
Mitigation:
Apply the latest patch or update to a non-vulnerable version of IrfanView. Avoid opening untrusted .ani files.