CVE-2012-0276: Buffer Overflow
Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a (1) SGI32LogLum compressed TIFF image or (2) SGI32LogLum compressed TIFF image with the PhotometricInterpretation encoding set to LogL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0276?
CVE-2012-0276 has a high severity rating due to the potential for remote code execution and denial of service.
How do I fix CVE-2012-0276?
To mitigate CVE-2012-0276, users should upgrade to XnView version 1.99 or later.
What causes the vulnerability in CVE-2012-0276?
CVE-2012-0276 is caused by multiple heap-based buffer overflows when processing specific TIFF images.
What types of images are affected by CVE-2012-0276?
CVE-2012-0276 affects SGI32LogLum compressed TIFF images, particularly those with certain encoding settings.
Can CVE-2012-0276 lead to data loss?
While CVE-2012-0276 primarily leads to application crashes, it may also result in data loss if the application fails to save the current state.