Heap-Based Buffer Overflow in XnView Software by Xjp2.dll
CVE-2013-3941

9.8CRITICAL

Key Information:

Vendor

Xnview

Status
Vendor
CVE Published:
2 January 2020

What is CVE-2013-3941?

The Xjp2.dll file in XnView prior to version 2.13 is susceptible to vulnerabilities that enable remote attackers to execute arbitrary code. This can be exploited through specially crafted JPEG2000 files. The vulnerability may occur via a flawed memory allocation triggered by manipulating the Csiz parameter within a SIZ marker, or by tampering with the lqcd field in a QCD marker. Both scenarios can lead to critical memory management errors, allowing attackers to gain unauthorized access and control over the affected systems.

Affected Version(s)

XnView before 2.13

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.