CVE-2017-15242

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
11/10/2017
Last modified:
20/04/2025

Description

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "User Mode Write AV starting at PDF!xmlGetGlobalState+0x0000000000031abe."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:irfanview:irfanview:4.44:*:*:*:*:*:x86:*
cpe:2.3:a:irfanview:pdf:4.43:*:*:*:*:*:*:*