CVE-2013-3937: Buffer Overflow
Published Jan 2, 2020
·Updated
Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in a BMP file.
Affected Software
1 affected component
XnView xnview<2.13
Event History
Jan 2, 2020
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2013-3937?
CVE-2013-3937 is a vulnerability that allows remote attackers to execute arbitrary code in XnView before version 2.13.
2
How severe is CVE-2013-3937?
CVE-2013-3937 has a severity rating of 7.8 (high).
3
What is the affected software of CVE-2013-3937?
The affected software of CVE-2013-3937 is XnView before version 2.13.
4
How can I fix CVE-2013-3937?
To fix CVE-2013-3937, you should update XnView to version 2.13 or later.
5
Are there any additional references for CVE-2013-3937?
Yes, you can refer to the following links for more information on CVE-2013-3937: [http://newsgroup.xnview.com/viewtopic.php?f=35&t=29087](http://newsgroup.xnview.com/viewtopic.php?f=35&t=29087) and [http://secunia.com/advisories/52101](http://secunia.com/advisories/52101).