Heap-based buffer overflow in IrfanView - CVE-2013-5351
Published: February 14, 2014 / Updated: August 10, 2020
IrfanView
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Heap-based buffer overflow in IrfanView before 4.37. A remote attacker can use the LZW code stream in a GIF file. to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
How to mitigate CVE-2013-5351
Sources
- http://osvdb.org/101065
- http://secunia.com/advisories/54959
- http://secunia.com/secunia_research/2013-13/
- http://www.irfanview.com/main_history.htm
- http://www.securityfocus.com/bid/64388
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89808
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89820