Vulnerability Description
Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Irfanview | Irfanview | <= 4.36 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN63194482/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000120
- http://www.irfanview.com/main_history.htm
- http://jvn.jp/en/jp/JVN63194482/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000120
- http://www.irfanview.com/main_history.htm
FAQ
What is CVE-2013-6932?
CVE-2013-6932 is a vulnerability with a CVSS score of 7.6 (HIGH). Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly hand...
How severe is CVE-2013-6932?
CVE-2013-6932 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6932?
Check the references section above for vendor advisories and patch information. Affected products include: Irfanview Irfanview.