Vulnerability Description
Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Irfanview | Irfanview | 4.23 |
Related Weaknesses (CWE)
References
- http://osvdb.org/55150
- http://secunia.com/advisories/35359Vendor Advisory
- http://www.irfanview.com/main_history.htmPatchVendor Advisory
- http://www.securityfocus.com/bid/35423Patch
- http://osvdb.org/55150
- http://secunia.com/advisories/35359Vendor Advisory
- http://www.irfanview.com/main_history.htmPatchVendor Advisory
- http://www.securityfocus.com/bid/35423Patch
FAQ
What is CVE-2009-2118?
CVE-2009-2118 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-bas...
How severe is CVE-2009-2118?
CVE-2009-2118 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-2118?
Check the references section above for vendor advisories and patch information. Affected products include: Irfanview Irfanview.