CVE-2010-1509 Information
Feb 14, 2021
cve
Description
IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow related to a \sign-extension error.\
Reference
http://irfanview.com/main_history.htm http://osvdb.org/64627 http://secunia.com/advisories/39036 http://secunia.com/secunia_research/2010-41 http://www.securityfocus.com/archive/1/511274/100/0/threaded http://www.securityfocus.com/bid/40104 https://exchange.xforce.ibmcloud.com/vulnerabilities/58548 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A6705
Share on: