CVE-2017-14272: Buffer Overflow
Published Sep 11, 2017
·Updated
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at jbig2dec+0x000000000000595d."
Affected Software
2 affected components
XnView xnview=2.40
Microsoft Windows
Event History
Sep 11, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14272?
CVE-2017-14272 has a high severity rating due to the potential for arbitrary code execution.
2
How do I fix CVE-2017-14272?
To fix CVE-2017-14272, upgrade XnView Classic to a version later than 2.40 that addresses this vulnerability.
3
What systems are affected by CVE-2017-14272?
CVE-2017-14272 specifically affects XnView Classic version 2.40 on Windows.
4
What type of attacks can CVE-2017-14272 enable?
CVE-2017-14272 can enable attackers to execute arbitrary code or cause a denial of service.
5
Is there a workaround for CVE-2017-14272?
Currently, the most effective workaround for CVE-2017-14272 is to avoid opening untrusted .jb2 files in XnView Classic version 2.40.