CVE-2013-3939
xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based buffer overflow.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.73% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- xnview/xnview
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://newsgroup.xnview.com/viewtopic.php?f=35&t=29087Permissions Required, Vendor Advisory
- http://secunia.com/advisories/52101Not Applicable, Vendor Advisory
- http://newsgroup.xnview.com/viewtopic.php?f=35&t=29087Permissions Required, Vendor Advisory
- http://secunia.com/advisories/52101Not Applicable, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.