CVE-2021-46064

IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image.
References
Link Resource
http://irfan.com Product URL Repurposed
http://irfanview.com Product
https://www.irfanview.info/main_history.htm Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:irfanview:irfanview:4.59:*:*:*:*:*:x86:*

History

14 Feb 2024, 01:17

Type Values Removed Values Added
References () http://irfan.com - Product () http://irfan.com - Product, URL Repurposed

29 Mar 2022, 00:43

Type Values Removed Values Added
First Time Irfanview irfanview
Irfanview
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
CPE cpe:2.3:a:irfanview:irfanview:4.59:*:*:*:*:*:x86:*
CWE CWE-120
References (MISC) http://irfan.com - (MISC) http://irfan.com - Product
References (MISC) https://www.irfanview.info/main_history.htm - (MISC) https://www.irfanview.info/main_history.htm - Release Notes, Vendor Advisory
References (MISC) http://irfanview.com - (MISC) http://irfanview.com - Product

23 Mar 2022, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-23 18:15

Updated : 2024-02-14 01:17


NVD link : CVE-2021-46064

Mitre link : CVE-2021-46064

CVE.ORG link : CVE-2021-46064


JSON object : View

Products Affected

irfanview

  • irfanview
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')