CVE-2017-15787: Buffer Overflow
Published Oct 22, 2017
·Updated
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation starting at xnview+0x0000000000580063."
Affected Software
2 affected components
XnView xnview=2.43
Microsoft Windows
Event History
Oct 22, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15787?
CVE-2017-15787 is considered a high severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2017-15787?
To fix CVE-2017-15787, update XnView Classic to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2017-15787?
CVE-2017-15787 is a remote code execution vulnerability that can also lead to a denial of service.
4
What software is affected by CVE-2017-15787?
CVE-2017-15787 affects XnView Classic version 2.43 running on Windows operating systems.
5
Can CVE-2017-15787 be exploited through file uploads?
Yes, attackers can exploit CVE-2017-15787 by uploading a specially crafted .dwg file.