Buffer Overflow Vulnerability in XnView by XnSoft
CVE-2013-3939
7.8HIGH
What is CVE-2013-3939?
The vulnerability in XnView prior to version 2.13 is due to improper handling of RLE strip lengths while processing RGB files. An attacker can exploit this flaw by crafting a malicious RGB file that, when processed by the affected application, can trigger an unexpected sign extension error and result in a heap-based buffer overflow. This can lead to arbitrary code execution, allowing attackers to gain control of the affected system.
Affected Version(s)
XnView before 2.13
