First published: Tue Jul 17 2012(Updated: )
Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a (1) SGI32LogLum compressed TIFF image or (2) SGI32LogLum compressed TIFF image with the PhotometricInterpretation encoding set to LogL.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xnview Xnview | <=1.98.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0276 has a high severity rating due to the potential for remote code execution and denial of service.
To mitigate CVE-2012-0276, users should upgrade to XnView version 1.99 or later.
CVE-2012-0276 is caused by multiple heap-based buffer overflows when processing specific TIFF images.
CVE-2012-0276 affects SGI32LogLum compressed TIFF images, particularly those with certain encoding settings.
While CVE-2012-0276 primarily leads to application crashes, it may also result in data loss if the application fails to save the current state.