First published: Mon Sep 11 2017(Updated: )
XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77400000!RtlInterlockedPopEntrySList+0x000000000000039b."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XnView | =2.40 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14285 is rated as a high severity vulnerability due to its potential to cause a denial of service.
To mitigate CVE-2017-14285, upgrade to the latest version of XnView or implement file validation to prevent processing of crafted .jb2 files.
CVE-2017-14285 specifically affects XnView Classic for Windows Version 2.40.
CVE-2017-14285 can cause a denial of service or potentially allow for other unspecified impacts.
CVE-2017-14285 was reported by security researchers focusing on vulnerabilities in graphics processing software.