IrfanView 4.33 DJVU Image Processing is prone to a heap overflow vulnerability
Credit:
The information has been provided by Francis Provencher .
Vulnerable Systems:
* IrfanView 4.33 DJVU Image Processing
The vulnerability is caused due to an error when decompressing DjVu images and can be exploited to cause a heap-based buffer overflow via a specially crafted file.
http://protekresearchlab.com/exploits/PRL-2012-23.djvu
http://www.exploit-db.com/sploits/19385.djvu
CVE Information:
2012-3585
Disclosure Timeline:
2012-05-15 - Vulnerability reported to secunia
2012-06-22 - Coordinated public release of advisory
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by