CVE-2013-3939

CVE-2013-3939: vulnerability in XnView

Published · Updated

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.7%
exploitation probability
1.7%top 23% of all CVEs
observed exploitation
nono source reports it
xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based buffer overflow.
Affected products
XnView · XnView