CVE-2017-15774: Buffer Overflow
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls Code Flow starting at CADImage+0x0000000000221a9a."
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15774?
CVE-2017-15774 is a vulnerability in XnView Classic for Windows Version 2.43 that allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file.
What versions of XnView are affected by CVE-2017-15774?
XnView Classic for Windows Version 2.43 is the only affected version as noted in CVE-2017-15774.
How do I fix CVE-2017-15774?
To fix CVE-2017-15774, update XnView Classic to the latest version that resolves the vulnerability.
What are the potential impacts of CVE-2017-15774?
The potential impacts of CVE-2017-15774 include arbitrary code execution and denial of service affecting the application.
Is XnView Classic safe to use with CVE-2017-15774?
XnView Classic is not safe to use in its 2.43 version due to the risks associated with CVE-2017-15774 until patched.