Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
XnView DICOM Parsing Integer Overflow Vulnerability (Windows)
Information
Severity
Severity
Critical
Family
Family
Buffer overflow
CVSSv2 Base
CVSSv2 Base
9.3
CVSSv2 Vector
CVSSv2 Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Solution Type
Solution Type
Vendor Patch
Created
Created
14 years ago
Modified
Modified
5 years ago
Summary
This host has XnView installed and is prone to integer overflow vulnerability. Vulnerabilities Insight: The flaw is due to integer overflow when processing DICOM images with certain dimensions. This can be exploited to cause a heap-based buffer overflow by persuading a victim to open a specially-crafted DICOM image file.
Affected Software
Affected Software
XnView versions prior to 1.97.2 on windows
Solution
Solution
Update to XnView version 1.97.2