CVE-2013-6932

Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:irfanview:irfanview:*:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.00:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.10:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.20:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.23:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.25:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.27:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.28:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.30:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.32:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.33:*:*:*:*:*:*:*
cpe:2.3:a:irfanview:irfanview:4.35:*:*:*:*:*:*:*

History

21 Nov 2024, 01:59

Type Values Removed Values Added
References () http://jvn.jp/en/jp/JVN63194482/index.html - () http://jvn.jp/en/jp/JVN63194482/index.html -
References () http://jvndb.jvn.jp/jvndb/JVNDB-2013-000120 - () http://jvndb.jvn.jp/jvndb/JVNDB-2013-000120 -
References () http://www.irfanview.com/main_history.htm - () http://www.irfanview.com/main_history.htm -

Information

Published : 2013-12-28 04:53

Updated : 2024-11-21 01:59


NVD link : CVE-2013-6932

Mitre link : CVE-2013-6932

CVE.ORG link : CVE-2013-6932


JSON object : View

Products Affected

irfanview

  • irfanview
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer