PT-2019-19964 · Xnview · Xnview Classic+1

Code16

·

Published

2019-03-23

·

Updated

2019-03-25

·

CVE-2019-9966

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions XnView Classic version 2.48
Description The issue allows remote attackers to cause a denial of service, potentially leading to an application crash, or possibly have other unspecified impacts via a crafted file. This is related to the xnview+0x38536c function.
Recommendations For XnView Classic version 2.48, consider avoiding the use of crafted files that may trigger the denial of service until a patch is available. As a temporary workaround, restrict the opening of potentially malicious files in XnView Classic to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9966

Affected Products

Xnview Classic
Xnview