CVE-2017-2813
Description
An exploitable integer overflow vulnerability exists in the JPEG 2000 parser functionality of IrfanView 4.44. A specially crafted jpeg2000 image can cause an integer overflow leading to wrong memory allocation resulting in arbitrary code execution. Vulnerability can be triggered by viewing the image in via the application or by using thumbnailing feature of IrfanView.
Risk Information
Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.363
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| update irfanview 4.44 to latest version | Windows |
| update irfanview 4.44 (x64) to latest version | Windows |
| Multiple Vulnerabilities are affected in IrfanView (64-bit) 4.44 | Windows |
| Multiple Vulnerabilities are affected in IrfanView 4.44 | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-342180 | IrfanView (4.70) |
| PATCH-342181 | IrfanView (64-bit) (4.70) |
| PATCH-347987 | IrfanView (x64) (4.72) |
| PATCH-349811 | IrfanView (4.72) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234