CVE-2017-9903: Buffer Overflow
Published Jul 5, 2017
·Updated
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at Xfpx+0x00000000000117ff."
Affected Software
1 affected component
XnView xnview=2.40
Event History
Jul 5, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9903?
CVE-2017-9903 is considered a critical vulnerability as it allows remote code execution through a malicious .fpx file.
2
How can I fix CVE-2017-9903?
To fix CVE-2017-9903, it is recommended to update XnView Classic to the latest version that addresses this vulnerability.
3
What types of attacks can leverage CVE-2017-9903?
CVE-2017-9903 can be exploited by attackers to execute arbitrary code on a victim's machine when a crafted .fpx file is opened.
4
Are there any workarounds for CVE-2017-9903?
A temporary workaround for CVE-2017-9903 is to avoid opening .fpx files from untrusted sources.
5
Which versions of XnView are impacted by CVE-2017-9903?
CVE-2017-9903 specifically affects XnView Classic version 2.40.