CVE-2013-3939 Information
Feb 14, 2021
cve
Description
xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file which leads to an unexpected sign extension error and a heap-based buffer overflow.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://newsgroup.xnview.com/viewtopic.php?f=35&t=29087 http://secunia.com/advisories/52101
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: