First published: Mon Jul 11 2011(Updated: )
Untrusted search path vulnerability in XnView before 1.98.1 allows local users to gain privileges via a Trojan horse .exe file in a folder selected by the "Open containing folder" menu item.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Xnview Xnview | =1.80.1 | |
Xnview Xnview | =1.80.3 | |
Xnview Xnview | <=1.98 | |
Xnview Xnview | =1.80 | |
Xnview Xnview | =1.74 | |
Xnview Xnview | =1.82 | |
Xnview Xnview | =1.80.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1338 has a medium severity level due to the potential for local users to escalate privileges.
To fix CVE-2011-1338, update XnView to version 1.98.1 or later.
CVE-2011-1338 affects all versions of XnView prior to 1.98.1.
CVE-2011-1338 is an untrusted search path vulnerability.
No, CVE-2011-1338 requires local user access to exploit.