Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Formats | Irfanview | * | 4.22 (including) |
Formats | Irfanview | 4.00 (including) | 4.00 (including) |
Formats | Irfanview | 4.10 (including) | 4.10 (including) |
Formats | Irfanview | 4.20 (including) | 4.20 (including) |