IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x000000000000839c.
References
Link | Resource |
---|---|
https://www.irfanview.com/main_history.htm | Release Notes Vendor Advisory |
https://github.com/linhlhq/research/blob/master/README.md | Third Party Advisory |
Configurations
Information
Published : 2019-10-08 05:15
Updated : 2019-10-10 07:55
NVD link : CVE-2019-17258
Mitre link : CVE-2019-17258
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
irfanview
- irfanview