CVE-2013-3247: Buffer Overflow
Published Jan 2, 2020
·Updated
Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file.
Affected Software
1 affected component
XnView xnview<2.03
Event History
Jan 2, 2020
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2013-3247?
CVE-2013-3247 is a heap-based buffer overflow vulnerability in XnView that allows remote attackers to execute arbitrary code.
2
How does CVE-2013-3247 impact XnView?
CVE-2013-3247 allows remote attackers to execute arbitrary code in XnView.
3
What is the severity of CVE-2013-3247?
CVE-2013-3247 has a severity rating of 7.8 (High).
4
How can I fix CVE-2013-3247?
To fix CVE-2013-3247, update XnView to version 2.03 or later.
5
Where can I find more information about CVE-2013-3247?
For more information about CVE-2013-3247, you can visit the following references: [1] FuzzMyApp Advisory: http://www.fuzzmyapp.com/advisories/FMA-2013-003/FMA-2013-003-EN.xml [2] IBM X-Force Exchange: https://exchange.xforce.ibmcloud.com/vulnerabilities/84642