Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.fuzzmyapp.com/advisories/FMA-2013-003/FMA-2013-003-EN.xml | third party advisory exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/84642 | vdb entry third party advisory |