← Back

CVE-2013-3939

nvd nist
Published: Jan 2, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based buffer overflow.

Affected (1)

Products: Xnview: Xnview
1 product
Xnview
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.13

References (4)

Source: PSIRT-CNA@flexerasoftware.com
Permissions RequiredVendor Advisory
Source: PSIRT-CNA@flexerasoftware.com
Not ApplicableVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableVendor Advisory

Timeline

No history available yet.