IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls subsequent Write Address starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000a525."
| Software | From | Fixed in |
|---|---|---|
| irfanview / irfanview | 4.44 | 4.44.x |
| irfanview / fpx | 4.46 | 4.46.x |