CVE-2018-15176: Buffer Overflow
Published Aug 8, 2018
·Updated
XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x0000000000000074 and application crash) or possibly have unspecified other impact via a crafted RLE file.
Affected Software
1 affected component
XnView xnview=2.45
Event History
Aug 8, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-15176?
CVE-2018-15176 is a vulnerability in XnView 2.45 that allows remote attackers to cause a denial of service or potentially have unspecified other impact via a crafted RLE file.
2
How severe is CVE-2018-15176?
CVE-2018-15176 has a severity rating of 7.8 (high).
3
Which software version is affected by CVE-2018-15176?
XnView version 2.45 is affected by CVE-2018-15176.
4
How can I fix CVE-2018-15176?
To fix CVE-2018-15176, update XnView to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2018-15176?
For more information about CVE-2018-15176, you can refer to the following link: http://code610.blogspot.com/2018/08/updating-xnview.html