XnView DLL Loading Arbitrary Code Execution Vulnerability
BID:48562
Info
XnView DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 48562 |
| Class: | Design Error |
| CVE: |
CVE-2011-1338 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2011 12:00AM |
| Updated: | Jul 05 2011 12:00AM |
| Credit: | Makoto Shiotsuki |
| Vulnerable: |
XnView XnView 1.90.3 XnView XnView 1.98 |
| Not Vulnerable: |
XnView XnView 1.98.1 |
Discussion
XnView DLL Loading Arbitrary Code Execution Vulnerability
XnView is prone to an arbitrary-code-execution vulnerability.
Attackers can exploit this vulnerability to execute arbitrary code in the context of the user running the vulnerable application.
XnView versions prior to 1.98.1 are vulnerable.
XnView is prone to an arbitrary-code-execution vulnerability.
Attackers can exploit this vulnerability to execute arbitrary code in the context of the user running the vulnerable application.
XnView versions prior to 1.98.1 are vulnerable.
Exploit / POC
XnView DLL Loading Arbitrary Code Execution Vulnerability
To exploit this issue, attackers must trick a user into opening a file on a remote WebDAV or SMB share.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
To exploit this issue, attackers must trick a user into opening a file on a remote WebDAV or SMB share.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Solution / Fix
XnView DLL Loading Arbitrary Code Execution Vulnerability
Solution:
A vendor update is available. Please see the references for more information.
Solution:
A vendor update is available. Please see the references for more information.
References
XnView DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Exploiting DLL Hijacking Flaws (hdm)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- XnView executable load files insecurely (JVN)
- XnView Homepage (XnView)
- Microsoft Security Advisory (2269637) (Microsoft)