← back
CVE-2013-3946

CVE-2013-3946

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 2.5%
exploitation probability
2.5%top 17% of all CVEs
observed exploitation
nono source reports it
In short

A security flaw in IrfanView's MrSID image plugin allows attackers to crash the program or run malicious code by opening a specially crafted image file with a corrupted levels header.

Technical detail

Heap-based buffer overflow in MrSID.dll (versions before 4.37) triggered via malformed levels header in MrSID image files; remote attack vector requiring user to open crafted file; results in code execution with privileges of the application user.

Summary generated and translated by AI from the official description.
Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a levels header.
Affected products
IrfanView · MrSID plugin