CVE-2013-3246: Buffer Overflow
Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer in an XCF file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2013-3246?
CVE-2013-3246 is a stack-based buffer overflow vulnerability in XnView before version 2.03.
What is the severity of CVE-2013-3246?
CVE-2013-3246 has a severity level of 7.8 (high).
How does CVE-2013-3246 affect XnView?
CVE-2013-3246 allows remote attackers to execute arbitrary code in XnView before version 2.03 by exploiting a stack-based buffer overflow in xnview.exe.
What is the Common Weakness Enumeration (CWE) ID for CVE-2013-3246?
CVE-2013-3246 has two CWE IDs: CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-787 (Out-of-bounds Write).
Are there any references for CVE-2013-3246?
Yes, below are the references for CVE-2013-3246: - http://www.fuzzmyapp.com/advisories/FMA-2013-003/FMA-2013-003-EN.xml - https://exchange.xforce.ibmcloud.com/vulnerabilities/84643