Multiple heap-based buffer overflow vulnerabilities in XnView via a SGI32LogLum compressed TIFF image or SGI32LogLum compressed TIFF image with the PhotometricInterpretation encoding set to LogLID: oval:org.secpod.oval:def:6407 | Date: (C)2012-07-18 (M)2021-06-02 |
Class: VULNERABILITY | Family: windows |
The host is installed with XnView before 1.99 and is prone to multiple heap-based buffer overflow vulnerabilities. The flaws are present in the application, which fails to handle a SGI32LogLum compressed TIFF image or SGI32LogLum compressed TIFF image with the PhotometricInterpretation encoding set to LogL. Successful exploitation allows remote attackers to cause a denial of service.
Platform: |
Microsoft Windows 2000 |
Microsoft Windows 7 |
Microsoft Windows Server 2003 |
Microsoft Windows Server 2008 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows Vista |
Microsoft Windows XP |