Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.801338
Kategorie:Buffer overflow
Titel:IrfanView Buffer Overflow Vulnerabilities
Zusammenfassung:IrfanView is prone to buffer overflow vulnerabilities.
Beschreibung:Summary:
IrfanView is prone to buffer overflow vulnerabilities.

Vulnerability Insight:
The flaws are due to:

- A sign extension error when parsing certain 'PSD' images

- A boundary error when processing certain 'RLE' compressed 'PSD' images.

These can be exploited to cause a heap-based buffer overflow by tricking a
user into opening a specially crafted PSD file.

Vulnerability Impact:
Successful exploitation will allow attacker to allow execution of arbitrary
code or to compromise a user's system.

Affected Software/OS:
IrfanView version prior to 4.27

Solution:
Upgrade to version 4.27 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2010-1510
BugTraq ID: 40105
http://www.securityfocus.com/bid/40105
Bugtraq: 20100512 Secunia Research: IrfanView PSD RLE Decompression Buffer Overflow (Google Search)
http://www.securityfocus.com/archive/1/511275/100/0/threaded
http://secunia.com/secunia_research/2010-42
http://osvdb.org/64628
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7397
http://secunia.com/advisories/39036
XForce ISS Database: irfanview-rle-psd-bo(58549)
https://exchange.xforce.ibmcloud.com/vulnerabilities/58549
Common Vulnerability Exposure (CVE) ID: CVE-2010-1509
BugTraq ID: 40104
http://www.securityfocus.com/bid/40104
Bugtraq: 20100512 Secunia Research: IrfanView PSD Image Parsing Sign-Extension Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/511274/100/0/threaded
http://secunia.com/secunia_research/2010-41
http://osvdb.org/64627
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6705
XForce ISS Database: irfanview-psd-bo(58548)
https://exchange.xforce.ibmcloud.com/vulnerabilities/58548
CopyrightCopyright (C) 2010 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.