CVE-2012-0276

Description

Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a (1) SGI32LogLum compressed TIFF image or (2) SGI32LogLum compressed TIFF image with the PhotometricInterpretation encoding set to LogL.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
14.934

Associated Vulnerability

VulnerabilityOS Platform
update xnview 1.98.8 to latest versionWindows
update xnview 1.98.8 to latest version (For Ubuntu)Linux
update xnview 1.98.8 to latest version (For Debian)Linux
update xnview 1.98.8 to latest version (For Centos)Linux
update xnview 1.98.8 to latest version (For RedHat)Linux
update xnview 1.98.8 to latest version (For Suse)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234