CVE-2018-15174: Buffer Overflow
Published Aug 8, 2018
·Updated
XnView 2.45 allows remote attackers to cause a denial of service (Read Access Violation at the Instruction Pointer and application crash) or possibly have unspecified other impact via a crafted ICO file.
Affected Software
1 affected component
XnView xnview=2.45
Event History
Aug 8, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for XnView 2.45?
The vulnerability ID for XnView 2.45 is CVE-2018-15174.
2
What is the impact of the vulnerability CVE-2018-15174?
The vulnerability CVE-2018-15174 can cause a denial of service (Read Access Violation at the Instruction Pointer and application crash) or possibly have unspecified other impact.
3
How can remote attackers exploit CVE-2018-15174?
Remote attackers can exploit CVE-2018-15174 by sending a crafted ICO file to the vulnerable XnView application.
4
Is there a fix available for the vulnerability CVE-2018-15174?
Yes, updating XnView to a version beyond 2.45 can fix the vulnerability CVE-2018-15174.
5
What is the Common Weakness Enumeration (CWE) ID for the vulnerability CVE-2018-15174?
The Common Weakness Enumeration (CWE) ID for the vulnerability CVE-2018-15174 is CWE-119.