First published: Wed Apr 02 2008(Updated: )
Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long FontName parameter in a slideshow (.sld) file, a different vector than CVE-2008-1461.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
XnView | <=1.92 | |
XnView | <=1.92.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0069 has been classified with a high severity due to the potential for remote code execution.
To fix CVE-2008-0069, update XnView to version 1.92.2 or later.
CVE-2008-0069 affects XnView versions 1.92 and 1.92.1.
CVE-2008-0069 allows attackers to execute arbitrary code on a victim's machine.
CVE-2008-0069 is not considered a zero-day vulnerability as it was disclosed publicly in 2008.