CVE-2018-15175: Buffer Overflow
Published Aug 8, 2018
·Updated
XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVariant+0x0000000000000014 and application crash) or possibly have unspecified other impact via a crafted RLE file.
Affected Software
1 affected component
XnView xnview=2.45
Event History
Aug 8, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability identifier for this issue?
The vulnerability identifier for this issue is CVE-2018-15175.
2
What is the severity of CVE-2018-15175?
The severity of CVE-2018-15175 is high.
3
How can remote attackers exploit CVE-2018-15175?
Remote attackers can exploit CVE-2018-15175 by causing a denial of service or possibly have unspecified other impact via a crafted RLE file.
4
What is the affected software version for CVE-2018-15175?
The affected software version for CVE-2018-15175 is XnView 2.45.
5
Is there a fix available for CVE-2018-15175?
Yes, updating to a newer version of XnView is recommended to fix CVE-2018-15175.