PT-2005-5263 · Xnsoft+1 · Xnview+1

Krzysiek Pawlik

·

Publicado

2005-12-31

·

Atualizado

2017-07-20

·

CVE-2005-4595

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XnView version 1.70 NView version 4.51
Description The issue is related to an untrusted search path vulnerability, specifically an RPATH vulnerability, which allows local users to execute arbitrary code. This can be achieved by placing a malicious library in the current working directory.
Recommendations For XnView version 1.70, update to a version that fixes the RPATH vulnerability. For NView version 4.51, update to a version that fixes the RPATH vulnerability. As a temporary workaround, consider restricting the execution of libraries from untrusted sources in the current working directory until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4595

Produtos afetados

Nview
Xnview