IrfanView32 Image File Buffer Overflow Vulnerability
BID:781
Info
IrfanView32 Image File Buffer Overflow Vulnerability
| Bugtraq ID: | 781 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-1999-1112 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 09 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | Posted to Bugtraq on November 9, 1999 by UNYUN <[email protected]>. |
| Vulnerable: |
Irfan Skiljan IrfanView32 3.0.7 |
| Not Vulnerable: | |
Discussion
IrfanView32 Image File Buffer Overflow Vulnerability
IrfanView32, a freeware image viewer, has a problem in the handling of Adobe Photoshop generated jpegs. If a .jpg file is opened for viewing that contains the Adobe Photoshop marker in the header (8BPS) followed by a long string, the program will crash. It is possible to insert code in the string for execution.
IrfanView32, a freeware image viewer, has a problem in the handling of Adobe Photoshop generated jpegs. If a .jpg file is opened for viewing that contains the Adobe Photoshop marker in the header (8BPS) followed by a long string, the program will crash. It is possible to insert code in the string for execution.
Exploit / POC
IrfanView32 Image File Buffer Overflow Vulnerability
This exploit will generate a jpg image that when viewed by IrfanView will create a file, exp.com, in the root of C:. This file will then be executed.
This exploit will generate a jpg image that when viewed by IrfanView will create a file, exp.com, in the root of C:. This file will then be executed.
Solution / Fix
IrfanView32 Image File Buffer Overflow Vulnerability
Solution:
Irfan Skiljan has released version 3.10, available at:
http://stud1.tuwien.ac.at/~e9227474/iview310.zip
Solution:
Irfan Skiljan has released version 3.10, available at:
http://stud1.tuwien.ac.at/~e9227474/iview310.zip