Heap Overflow Vulnerability in XnView MP Product by XnView
CVE-2020-23886

5.5MEDIUM

Key Information:

Vendor

Xnview

Status
Vendor
CVE Published:
10 November 2021

What is CVE-2020-23886?

A heap overflow vulnerability was identified in XnView MP version 0.96.4, allowing attackers to exploit crafted pict files to trigger a denial of service. This vulnerability is linked to an issue within user mode memory management that can result in application crashes, thereby disrupting services and user access. It is essential for users to ensure they are operating on the latest version of XnView MP to mitigate potential risks related to this vulnerability.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.