PT-2005-4089 · Jan Kybic · Jan Kybic Bitmap Viewer
Felinemalice
·
Published
2005-10-23
·
Updated
2017-07-11
·
CVE-2005-3278
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Jan Kybic BitMap Viewer (BMV) version 1.2
Description
The issue is related to an integer overflow in the openpsfile function, which can be triggered by a PostScript (PS) file with a large number of pages value. This leads to a buffer overflow, allowing local users to execute arbitrary code.
Recommendations
For version 1.2, consider restricting the use of the openpsfile function until a patch is available, or avoid opening PostScript files with large page values to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jan Kybic Bitmap Viewer