Great Reviews!Need help setting up your website, installing Apache, PHP, MySQL, or RavenNuke(tm)?Need help customizing or designing scripts?Please contact us via the Contact Us option for further details and pricing.
DESCRIPTION: Secunia Research has discovered a vulnerability in IrfanView, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a boundary error when importing palette (*.pal) files. This can be exploited to cause a stack-based buffer overflow by tricking a user into importing a specially crafted palette (*.pal) file.
Successful exploitation allows execution of arbitrary code. The vulnerability is confirmed in version 4.00. Other versions may also be affected.
SOLUTION: Update to version 4.10.: http://www.irfanview.com/main_download_engl.htm
PROVIDED AND/OR DISCOVERED BY: Stefan Cornelius, Secunia Research.
ORIGINAL ADVISORY:
Secunia: http://secunia.com/secunia_research/2007-71/
IrfanView: http://www.irfanview.com/main_history.htm
Posted on Tuesday, October 16, 2007 @ 18:30:06 EDT by Raven