Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, leading to a heap-based buffer overflow.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://newsgroup.xnview.com/viewtopic.php?f=35&t=19469 - Patch | |
References | () http://secunia.com/secunia_research/2009-60/ - | |
References | () http://www.osvdb.org/62829 - | |
References | () http://www.securityfocus.com/archive/1/509999/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/38629 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/56802 - |
Information
Published : 2010-03-15 13:28
Updated : 2025-04-11 00:51
NVD link : CVE-2009-4001
Mitre link : CVE-2009-4001
CVE.ORG link : CVE-2009-4001
JSON object : View
Products Affected
xnview
- xnview
CWE
CWE-189
Numeric Errors