First published: Thu Jan 02 2020(Updated: )
xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based buffer overflow.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xnview Xnview | <2.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2013-3939.
The severity of CVE-2013-3939 is high, with a severity value of 7.8.
CVE-2013-3939 occurs due to a heap-based buffer overflow in xnview.exe when processing RGB files with improperly handled RLE strip lengths.
XnView versions before 2.13 are affected by CVE-2013-3939.
To fix CVE-2013-3939, it is recommended to update XnView to version 2.13 or later.