VulnerabilityModified
CVE-2009-2118
Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.
MEDIUM 6.8EPSS 2.51%
Does this matter?
Lower severity and a low EPSS score (2.51%). Track it; it rarely justifies an emergency change on its own.
Description
Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.51% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- irfanview/irfanview
- Source
- cve@mitre.org
References
- http://osvdb.org/55150
- http://secunia.com/advisories/35359Vendor Advisory
- http://www.irfanview.com/main_history.htmPatch, Vendor Advisory
- http://www.securityfocus.com/bid/35423Patch
- http://osvdb.org/55150
- http://secunia.com/advisories/35359Vendor Advisory
- http://www.irfanview.com/main_history.htmPatch, Vendor Advisory
- http://www.securityfocus.com/bid/35423Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.