Heap-based buffer overflow in IrfanView before 4.32 allows remote attackers to execute arbitrary code via crafted "Rows Per Strip" and "Samples Per Pixel" values in a TIFF image file.
2012-10-25T17:55:07.890
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | irfanview | irfanview | ≤ 4.30 | Yes |
Application | irfanview | irfanview | 3.90 | Yes |
Application | irfanview | irfanview | 3.91 | Yes |
Application | irfanview | irfanview | 3.92 | Yes |
Application | irfanview | irfanview | 3.95 | Yes |
Application | irfanview | irfanview | 3.97 | Yes |
Application | irfanview | irfanview | 3.98 | Yes |
Application | irfanview | irfanview | 3.99 | Yes |
Application | irfanview | irfanview | 4.00 | Yes |
Application | irfanview | irfanview | 4.10 | Yes |
Application | irfanview | irfanview | 4.20 | Yes |
Application | irfanview | irfanview | 4.23 | Yes |
Application | irfanview | irfanview | 4.25 | Yes |
Application | irfanview | irfanview | 4.27 | Yes |
Application | irfanview | irfanview | 4.28 | Yes |