This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Irfanview First view 2024-08-21
Product Wsq Last view 2024-08-21
Version 2024.02.16 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software irfanview  
Target Hardware x64  
Other *  
 
CPE Product cpe:2.3:a:irfanview:wsq

Activity : Overall

Related : CVE

  Date Alert Description
7.8 2024-08-21 CVE-2024-6812

IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of WSQ files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23273.

7.8 2024-08-21 CVE-2024-6811

IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of WSQ files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24192.

CWE : Common Weakness Enumeration

%idName
100% (2) CWE-787 Out-of-bounds Write