PT-2008-1726 · Xnview · Xnview

Stefan Cornelius

·

Publicado

2008-04-02

·

Atualizado

2017-09-29

·

CVE-2008-0069

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions XnView versions 1.92 through 1.92.1
Description A stack-based buffer overflow issue allows user-assisted remote attackers to execute arbitrary code via a long FontName parameter in a slideshow (.sld) file.
Recommendations For versions 1.92 and 1.92.1, avoid using long FontName parameters in slideshow files until a fix is available. As a temporary workaround, consider restricting the use of slideshow files with potentially long FontName parameters to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0069

Produtos afetados

Xnview