CVE-2012-5904

IrfanView < 4.33 - Remote Code Execution via Crafted RLE Compressed Bitmap File

Title source: llm
STIX 2.1

Description

Heap-based buffer overflow in IrfanView before 4.33 allows remote attackers to execute arbitrary code via a crafted RLE compressed bitmap file such as a DIB, RLE, or BMP image.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52806
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47333
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80716
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74452
Various Sources x_refsource_confirm
http://www.irfanview.com/history_old.htm

Scores

EPSS 0.0842
EPSS Percentile 92.4%

Details

CWE
CWE-119
Status published
Products (50)
irfanview/irfanview 1.70
irfanview/irfanview 1.80
irfanview/irfanview 1.85
irfanview/irfanview 1.90
irfanview/irfanview 1.95
irfanview/irfanview 1.97
irfanview/irfanview 1.98
irfanview/irfanview 1.98a
irfanview/irfanview 1.99
irfanview/irfanview 2.00
... and 40 more
Published Nov 17, 2012
Tracked Since Feb 18, 2026