This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Irfanview updates

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://secunia.com/advisories/24725/
Last Update: 2007-04-30
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Upgrade to version 4.00
Software: IrfanView 3.x
…The vulnerability is confirmed in version 3.99. Prior versions may also be affected.
Solution: Upgrade to version 4.00.
http://www.irfanview.com/main_download_engl.htm …"

Note: Please use always the current IrfanView -and- PlugIn version …
http://www.irfanview.com/plugins.htm

.
FYI…

IrfanView vuln - update available
- http://secunia.com/advisories/35359/2/
Release Date: 2009-06-18
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: IrfanView 4.x …
Solution: Update to version 4.25.
http://irfanview.com/main_download_engl.htm …

Also: The current PlugIns version is: 4.25
- http://www.software.com/irfanview-plugin

- http://www.irfanview.net/main_history.htm
Release date: 2009-06-16

:ph34r:
FYI…

Irfanview vulns - update available
- http://secunia.com/advisories/39036/
Last Update: 2010-05-17
Criticality level: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Solution: Update to version 4.27.
- http://irfanview.com/main_download_engl.htm

Current PlugIns
- http://fileforum.betanews.com/download/Irf…ns/1099412658/1
irfanview_plugins_427_setup.exe

- http://irfanview.com/main_history.htm
Release date: 2010-05-09

- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2010-1509
- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2010-1510
Last revised: 05/21/2010

:ph34r:
FYI…

IrfanView v4.28 released
LuraDocument Format PlugIn Memory Corruption Vulnerability
- http://secunia.com/advisories/41439/
Release Date: 2010-12-17
Criticality level: Highly critical
Impact: System access
Where: From remote
Solution: No updated version of the plugin will be made available. The vendor has removed the plugin in version 4.28 of the plugins distribution.
Original Advisory:
http://irfanview.com/main_history.htm
Version 4.28 ( - CURRENT VERSION - ) (Release date: 2010-12-16)

:ph34r:
FYI…

IrfanView plugin JPEG-2000 v4.33 released
- https://secunia.com/advisories/47360/
Release Date: 2012-01-16
Criticality level: Moderately critical
Impact: System access
Where: From remote
… vulnerability is confirmed in version 4.32. Other versions may also be affected.
Solution: Update the JPEG2000 plug-in to version 4.33.

- http://www.irfanview.com/plugins.htm
… PlugIns updated after the version 4.32:
JPEG-2000 Plugin (4.33) - fixed crash/overflow with special files
> http://www.irfanview.net/plugins/irfanview…in_jpeg2000.exe

:ph34r:
FYI…

IrfanView v4.33 released
- https://secunia.com/advisories/47333/
Release Date: 2012-03-29
Criticality level: Highly critical
Impact: System access
Where: From remote …
… vulnerabilities are reported in versions prior to 4.33.
Solution: Update to version 4.33.

- http://www.irfanview.com/main_history.htm
Version 4.33 CURRENT VERSION - Release date: 2012-03-28

Download: http://www.irfanview.com/main_download_engl.htm

- http://www.irfanview.com/plugins.htm

:ph34r:
FYI…

IrfanView FlashPix PlugIn v4.34 released
- https://secunia.com/advisories/48772/
Release Date: 2012-04-13
Criticality level: Highly critical
Impact: System access
Where: From remote …
CVE Reference: CVE-2012-0278
Solution: Update to version 4.3.4.0…

- http://www.irfanview.com/plugins.htm
… PlugIns updated after the version 4.33:
FPX/FlashPix PlugIn (4.34):
- http://www.irfanview.net/plugins/irfanview_plugin_fpx.exe
… FPX-Library loading bug fixed
FYI…

IrfanView plugins updated - v4.34 released

- https://secunia.com/advisories/49204/
Release Date: 2012-05-31
Criticality level: Highly critical
Impact: System access
Where: From remote
… vulnerability is confirmed in version 4.33. Other versions may also be affected.
Solution: Apply ECW PlugIn patch version 4.34*
___

- http://www.irfanview.com/plugins.htm
PlugIns updated -after- the version 4.33:

FPX/FlashPix PlugIn (4.34): Installer or ZIP - FPX-Library loading bug fixed:
http://www.irfanview.net/plugins/irfanview_plugin_fpx.exe
* ECW PlugIn (Third party, 3.1.0.350 - 4.34): Installer or ZIP - Some loading bugs fixed:
http://www.irfanview.net/plugins/irfanview_plugin_ecw.exe
XCF PlugIn (1.08): Installer or ZIP - Some loading bugs fixed:
http://www.irfanview.net/plugins/irfanview_plugin_xcf.exe

- https://secunia.com/advisories/49319/
Release Date: 2012-06-01
Criticality level: Moderately critical
Impact: System access
Where: From remote…
Solution: Apply Formats PlugIn patch version 4.34…
- http://www.irfanview.com/plugins.htm
FORMATS PlugIn (4.34): TTF loading bug fixed…
- http://www.irfanview.net/plugins/irfanview…gin_formats.exe

:ph34r:
FYI…

IrfanView v4.35 released
TIFF Image Decompression Buffer Overflow Vulnerability
- https://secunia.com/advisories/49856/
Release Date: 2012-11-09
Criticality level: Highly critical
Impact: System access
Where: From remote
CVE Reference: https://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-5022 - 6.8
This is related to vulnerability #4 in: https://secunia.com/SA43593/
… vulnerability is confirmed in version 4.33. Other versions may also be affected.
Solution: Update to version 4.35.
Original Advisory: http://www.irfanview.com/main_history.htm
Version 4.35 - 2012-11-07

- http://www.irfanview.com/main_download_engl.htm

- http://www.irfanview.com/plugins.htm
The current PlugIns version is: 4.35

:ph34r:
FYI…

IrfanView FlashPix PlugIn FPX 4.36 released
- https://secunia.com/advisories/53579/
Release Date: 2013-05-30
Criticality level: Highly critical
Impact: System access
Where: From remote…
Software: IrfanView FlashPix PlugIn 4.x
CVE Reference: CVE-2013-3486
… vulnerability is caused due to an integer overflow error within the Fpx.dll module…
- http://www.irfanview.com/plugins.htm
PlugIns updated after the version 4.35:
FPX Plugin (4.36) - Installer or ZIP - Fixed loading of FPX (FlashPix) files (reported by Secunia)
- http://www.irfanview.net/plugins/irfanview_plugin_fpx.exe

:ph34r: :ph34r:
FYI…

IrfanView v4.36 released
- https://secunia.com/advisories/53976/
Release Date: 2013-07-05
Criticality: Highly Critical
Where: From remote
Impact: System access
Solution Status: Vendor Patch
Software: IrfanView 4.x
… vulnerability is confirmed in version 4.35. Prior versions may also be affected.
Solution: Update to version 4.36.

- http://www.irfanview.com/main_download_engl.htm

- http://www.irfanview.com/main_history.htm
Release date: 2013-06-27

- http://www.irfanview.com/plugins.htm
The current PlugIns version is: 4.36

:ph34r:

FYI…

IrfanView 4.37 released
- https://secunia.com/advisories/54959/
Release Date: 2013-12-17
Criticality: Highly Critical
Where: From remote
Impact: System access
CVE Reference(s): CVE-2013-5351
… vulnerability is confirmed in version 4.36. Prior versions may also be affected.
Solution: Update to version 4.37.
Original Advisory: IrfanView:
- http://www.irfanview.com/main_history.htm
Version 4.37 ( - CURRENT VERSION - ) (Release date: 2013-12-16)

- https://secunia.com/advisories/54444/
Release Date: 2013-12-17
Criticality: Highly Critical
Where: From remote
Impact: System access
CVE Reference(s): CVE-2013-3944, CVE-2013-3945, CVE-2013-3946
… vulnerabilities are confirmed in version 4.36. Prior versions may also be affected.
Solution: Updated to version 4.37.
Original Advisory: IrfanView:
- http://www.irfanview.com/plugins.htm
The current PlugIns version is: 4.37
___

- http://www.irfanview.com/main_download_engl.htm

Alternative download sites:
- http://www.majorgeeks.com/files/details/irfanview.html

- http://www.majorgeeks.com/files/details/irfanview_plugins.html
 

:ph34r: