CVE-2017-10736: Buffer Overflow
Published Jul 5, 2017
·Updated
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at msvcrt!VECmemzero+0x000000000000006a."
Affected Software
2 affected components
XnView xnview=2.40
Microsoft Windows
Event History
Jul 5, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10736?
CVE-2017-10736 has a medium severity rating due to the potential for arbitrary code execution.
2
How do I fix CVE-2017-10736?
To fix CVE-2017-10736, update to the latest version of XnView Classic beyond version 2.40.
3
What types of attacks can CVE-2017-10736 facilitate?
CVE-2017-10736 can facilitate arbitrary code execution or cause a denial of service when processing a malicious .rle file.
4
Which version of XnView is affected by CVE-2017-10736?
XnView Classic version 2.40 is the version affected by CVE-2017-10736.
5
What is the impact of CVE-2017-10736 on users?
The impact of CVE-2017-10736 on users can lead to system instability and compromise system security through arbitrary code execution.