CVE-2021-46064

IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image.
References
Link Resource
http://irfan.com Product URL Repurposed
http://irfanview.com Product
https://www.irfanview.info/main_history.htm Release Notes Vendor Advisory
http://irfan.com Product URL Repurposed
http://irfanview.com Product
https://www.irfanview.info/main_history.htm Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:irfanview:irfanview:4.59:*:*:*:*:*:x86:*

History

21 Nov 2024, 06:33

Type Values Removed Values Added
References () http://irfan.com - Product, URL Repurposed () http://irfan.com - Product, URL Repurposed
References () http://irfanview.com - Product () http://irfanview.com - Product
References () https://www.irfanview.info/main_history.htm - Release Notes, Vendor Advisory () https://www.irfanview.info/main_history.htm - Release Notes, Vendor Advisory

14 Feb 2024, 01:17

Type Values Removed Values Added
References (MISC) http://irfan.com - Product (MISC) http://irfan.com - Product, URL Repurposed

Information

Published : 2022-03-23 18:15

Updated : 2024-11-21 06:33


NVD link : CVE-2021-46064

Mitre link : CVE-2021-46064

CVE.ORG link : CVE-2021-46064


JSON object : View

Products Affected

irfanview

  • irfanview
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')