CVE-2017-9906: Buffer Overflow
Published Jul 5, 2017
·Updated
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at Xfpx!gffGetFormatInfo+0x0000000000028508."
Affected Software
1 affected component
XnView xnview=2.40
Event History
Jul 5, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9906?
CVE-2017-9906 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-9906?
To fix CVE-2017-9906, you should update XnView Classic to the latest version available.
3
What type of attack does CVE-2017-9906 facilitate?
CVE-2017-9906 allows remote attackers to cause a denial of service through a crafted .fpx file.
4
Which software versions are affected by CVE-2017-9906?
CVE-2017-9906 affects XnView Classic version 2.40.
5
What file type is involved in CVE-2017-9906?
CVE-2017-9906 involves the .fpx file type, which can trigger the vulnerability.