vendor:
IrfanView
by:
BraniX
5.5
CVSS
MEDIUM
Denial of Service
119
CWE
Product Name: IrfanView
Affected Version From: 4.28
Affected Version To: 4.28
Patch Exists: NO
Related CWE:
CPE: a:irfanview:irfanview:4.28
Platforms Tested: Windows XP SP3 Home Edition, Windows XP SP3 Professional
2011
IrfanView DoS Exploit
The DoS exploit is caused by an unhandled Access Violation Exception in the i_view32.exe module of IrfanView 4.28. It can be triggered by opening a specific icon file, either locally or remotely.
Mitigation:
Upgrade to a patched version of IrfanView.