PT-2020-7469 · Xnview · Xnview
Published
2020-01-02
·
Updated
2020-01-08
·
CVE-2013-3937
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
XnView versions prior to 2.13
Description:
The issue is related to a heap-based buffer overflow in the xnview.exe component of XnView. This occurs when processing the biBitCount field in a BMP file, allowing remote attackers to execute arbitrary code.
Recommendations:
For versions prior to 2.13, update to version 2.13 or later to resolve the issue. As a temporary workaround, consider avoiding the use of BMP files with potentially malicious biBitCount fields until the update is applied.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xnview