CVE-2017-14274: Buffer Overflow
Published Sep 11, 2017
·Updated
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at jbig2dec+0x0000000000008706."
Affected Software
2 affected components
XnView xnview=2.40
Microsoft Windows
Event History
Sep 11, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14274?
CVE-2017-14274 has a high severity level due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2017-14274?
To fix CVE-2017-14274, update XnView Classic to the latest version that has addressed this vulnerability.
3
What versions of XnView Classic are affected by CVE-2017-14274?
CVE-2017-14274 affects XnView Classic version 2.40.
4
What type of attacks can be executed using CVE-2017-14274?
CVE-2017-14274 allows attackers to execute arbitrary code or cause a denial of service by exploiting a crafted .jb2 file.
5
Can CVE-2017-14274 be exploited remotely?
Yes, CVE-2017-14274 can be exploited remotely if a user opens a malicious .jb2 file.