Release date:
Updated on:
Affected Systems:
XnView 1.98.5
XnView 1.98.2
XnView 1.98.1
XnView 1.98
XnView 1.90.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52057
XnView is a browser Image Viewer that supports multiple graphic formats.
XnView has multiple memory corruption vulnerabilities. After successful exploitation, attackers can execute arbitrary code.
<* Source: Luigi Auriemma (aluigi@pivx.com)
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.securityfocus.com/data/vulnerabilities/exploits/52057.zip
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
XnView
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.xnview.com/