CVE-2011-1338: Medium severity xnview vulnerability
Published Jul 11, 2011
·Updated
Untrusted search path vulnerability in XnView before 1.98.1 allows local users to gain privileges via a Trojan horse .exe file in a folder selected by the "Open containing folder" menu item.
Affected Software
7 affected components
XnView xnview=1.80.1
XnView xnview=1.80.3
XnView xnview<=1.98
XnView xnview=1.80
XnView xnview=1.74
XnView xnview=1.82
XnView xnview=1.80.2
Event History
Jul 11, 2011
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1338?
CVE-2011-1338 has a medium severity level due to the potential for local users to escalate privileges.
2
How do I fix CVE-2011-1338?
To fix CVE-2011-1338, update XnView to version 1.98.1 or later.
3
Who is affected by CVE-2011-1338?
CVE-2011-1338 affects all versions of XnView prior to 1.98.1.
4
What type of vulnerability is CVE-2011-1338?
CVE-2011-1338 is an untrusted search path vulnerability.
5
Can I exploit CVE-2011-1338 remotely?
No, CVE-2011-1338 requires local user access to exploit.