XnView Command-Line Arguments Buffer Overflow Vulnerability
BID:28259
Info
XnView Command-Line Arguments Buffer Overflow Vulnerability
| Bugtraq ID: | 28259 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1461 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 15 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Sylvain THUAL is credited with the discovery of this vulnerability. |
| Vulnerable: |
XnView XnView Standard 1.92.1 |
| Not Vulnerable: |
XnView XnView Standard 1.93.1 |
Discussion
XnView Command-Line Arguments Buffer Overflow Vulnerability
XnView is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers may exploit this issue only if XnView is configured as a handler for other applications, so that it can be passed malicious filenames as command-line data.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will result in a denial of service.
This issue affects XnView 1.92.1; other versions may also be vulnerable.
XnView is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers may exploit this issue only if XnView is configured as a handler for other applications, so that it can be passed malicious filenames as command-line data.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will result in a denial of service.
This issue affects XnView 1.92.1; other versions may also be vulnerable.
Exploit / POC
XnView Command-Line Arguments Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
XnView Command-Line Arguments Buffer Overflow Vulnerability
Solution:
The vendor has released XnView 1.93.1 to address this issue. Please see the references for more information.
Solution:
The vendor has released XnView 1.93.1 to address this issue. Please see the references for more information.
References
XnView Command-Line Arguments Buffer Overflow Vulnerability
References:
References:
- XnView Download Page (XnView)
- XnView History Page (XnView)
- XnView Homepage (XnView)
- XNview 1.92.1 Long Filename Overflow (Sylvain
)