XnView FontName Buffer Overflow Vulnerability
BID:28579
Info
XnView FontName Buffer Overflow Vulnerability
| Bugtraq ID: | 28579 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0069 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2008 12:00AM |
| Updated: | Apr 03 2008 05:39PM |
| Credit: | Stefan Cornelius from Secunia Research |
| Vulnerable: |
XnView XnView Standard 1.92.1 XnView XnView Standard 1.92 |
| Not Vulnerable: |
XnView XnView Standard 1.93.4 |
Discussion
XnView FontName Buffer Overflow Vulnerability
XnView is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will result in a denial of service.
This issue affects XnView 1.92.1; other versions may also be vulnerable.
XnView is prone to a buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will result in a denial of service.
This issue affects XnView 1.92.1; other versions may also be vulnerable.
Exploit / POC
XnView FontName Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
XnView FontName Buffer Overflow Vulnerability
Solution:
The vendor has released XnView 1.93.4. Please see the references for more information.
Solution:
The vendor has released XnView 1.93.4. Please see the references for more information.
References
XnView FontName Buffer Overflow Vulnerability
References:
References:
- XnView Download Page (XnView)
- XnView Homepage (XnView)
- XnView Slideshow "FontName" Buffer Overflow Vulnerability (Secunia Research)