Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Irfan View plugin vulnerability - fix available
Uniqs:
1114
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates 08 Apr 2009 »
« Congratulations To New and Re-Awardee 2009 MVP's  

EGeezer
Go Bobcats
Premium
join:2002-08-04
Country!

Irfan View plugin vulnerability - fix available

Thanks to governmentsecurity.org for the heads up and link;

»www.securityfocus.com/archive/1/502516

jaykaykay
4 Ever Young
Premium,MVM
join:2000-04-13
Scottsdale, AZ

Re: Irfan View plugin vulnerability - fix available

Thanks to you, many people will now get the heads up. So many people use that program and proabably wouldn't have known about it otherwise. Thank you, even though I nn longer use it.

EGeezer
Go Bobcats
Premium
join:2002-08-04
Country!

Re: Irfan View plugin vulnerability - fix available

I just hope the folks in dimaging see it -

exocet_cm
I am the law
Premium
join:2003-03-23
New Orleans, LA
clubs:
·Cox HSI
·Suddenlink
·Cingular Wireless
·AT&T Southeast
·Charter Pipeline

said by jaykaykay See Profile :

Thanks to you, many people will now get the heads up. So many people use that program and proabably wouldn't have known about it otherwise. Thank you, even though I nn longer use it.
I am one of those folks. Happened to see this thread title on the ticker from the front page.
--
"I have measured out my life with coffee spoons..." - T.S Eliot
"I have often regretted my speech, never my silence." - Publilius Syrus
Ma blog: »www.johndball.com

VikingBob

join:2004-06-05
Ste Anne, MB
Thanks muchly!

LadyL
Premium
join:2002-09-18
Lorain, OH

1 edit
It states to update to version 4.23 - which I've already had installed. I don't use any of the plug-ins. I very seldom use Irfanview, but thanks for the notification.
--
Lonnie

MarkAW
Barry White or lil bratt
Premium
join:2001-08-27
Canada
·Bell Sympatico
·Cogeco Cable


1 edit
Thanks EG, but aren't they a little behind on this since IrFan View has had Version 4.23 out since December 12 2008.
Version 4.23 ( - CURRENT VERSION - ) (Release date: 2008-12-29) »www.irfanview.net/

Plugins updated after the version 4.22:

# EXIF Plugin (4.23) - Installer or ZIP - fixes loading of some very large text tags (possible crash in EXIF plugin 4.22)

# FORMATS Plugin (4.23) - Installer or ZIP - fixes possible crash in loading of very large XPM images

# NERO Plugin (4.24) - Installer or ZIP - added option to burn CDs using Windows Burning Enegine (Windows XP or later)

RWild
Them Or Us
Premium
join:2003-09-15
Cary, NC
·AT&T Southeast
·Windstream
·Comcast
·RoadRunner Cable


1 edit

Re: Irfan View plugin vulnerability - fix available

I just tried to update using the link in your post and got version 4.22 of EXIF and FORMATS, and 4.20 for NERO.

Anybody else checked versions on these files?

Edit:

www.irfanview.com/plugins.htm, the link Exidor posted has the new stuff.

MarkAW
Barry White or lil bratt
Premium
join:2001-08-27
Canada
·Bell Sympatico
·Cogeco Cable

Re: Irfan View plugin vulnerability - fix available

Click for full size
said by RWild See Profile :

I just tried to update using the link in your post and got version 4.22 of EXIF and FORMATS, and 4.20 for NERO.

Anybody else checked versions on these files?

Edit:

www.irfanview.com/plugins.htm, the link Exidor posted has the new stuff.
Well i guess you didn't look hard enough.
--
Forget injuries, never forget kindnesses.

Reputation is what other people know about you. Honor is what you know about yourself.


Exidor
Premium
join:2001-05-04
Brampton, ON

»www.irfanview.com/plugins.htm

The current PlugIns version is: 4.22

Plugins updated after the version 4.22:

# EXIF Plugin (4.23) - fixes loading of some very large text tags (possible crash in EXIF plugin 4.22)

# FORMATS Plugin (4.23) - fixes possible crash in loading of very large XPM images

# NERO Plugin (4.24) - added option to burn CDs using Windows Burning Enegine (Windows XP or later)

jack b
Gone Fishing
Premium,MVM
join:2000-09-08
Cape Cod
clubs:
Thanks for the heads-up. I use this little gem of a program ALL the time!

cork1958
Cork

join:2000-02-26
Fruitport, MI
·Verizon Online DSL
·Charter Pipeline

Re: Irfan View plugin vulnerability - fix available

said by jack b See Profile :

Thanks for the heads-up. I use this little gem of a program ALL the time!
Yep,
Same here.

Install it on all computers I work on also.

Awesome little ditty!!

Thanks
--
The Firefox alternative.
»www.mozilla.org/projects/seamonkey/
grumpi

join:2001-03-28
*****

1 edit
I'd already updated when it was released but didn't know about this.
Thanks for the heads up!!

jbob
Reach Out and Touch Someone
Premium
join:2004-04-26
Little Rock, AR
·Comcast
·AT&T Southwest


2 edits
Ok I'm confused. The fix is to update to version 4.23. According to the Infranview website the current Plugins is still only at 4.22 while the program itself is at 4.23.

Am I missing something? It appears the Plugins update to 4.23 is not available yet. Unless they simply updated some of the modules in 4.22 with the later 4.23 versions.

Edit: Ok I think I see now. It's the Formats Plugin that needs to be updated. The full 4.22 Plugin archive includes the updated 4.23 Formats Plugin. Jeesh how confusing! lol

Edit2: Nope...you have to download the Formats Plugin separately.
SUMware
Premium
join:2002-05-21
Thanks!
Kearnstd
Elf Wizard
Premium
join:2002-01-22
Mullica Hill, NJ
wow good find, id never have thought of a hole in a stand alone program like iview.
--
[65 Arcanist]Filan(High Elf) Zone: Broadband Reports
Forums » Up and Running » Security » SecuritySecurity Software Updates 08 Apr 2009 »
« Congratulations To New and Re-Awardee 2009 MVP's  


Saturday, 05-Dec 10:52:45 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [126] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [95] The Bandwidth Hog Does Not Exist
· [84] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [79] New Bill Aims To Limit ETFs
· [74] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· False positive in Avast! or is it real? [Security]
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· DNS options, what are YOU using? [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· UPS - What do you people think happened? [General Questions]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· UBB round 2 at the CRTC [Canadian Broadband]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Road Runnner up to 50 mbps is ready ! [Road Runner]