CVE-2013-3946
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.5%
exploitation probability
2.5%top 17% of all CVEs
observed exploitation
nono source reports it
In short
A security flaw in IrfanView's MrSID image plugin allows attackers to crash the program or run malicious code by opening a specially crafted image file with a corrupted levels header.
Technical detail
Heap-based buffer overflow in MrSID.dll (versions before 4.37) triggered via malformed levels header in MrSID image files; remote attack vector requiring user to open crafted file; results in code execution with privileges of the application user.
Summary generated and translated by AI from the official description.
Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a levels header.
Affected products
IrfanView · MrSID plugin