3761Third-party advisory
http://securityreason.com/securityalert/3761 CVE-2008-1461
XnView 1.92.1 - Command-Line Arguments Buffer Overflow
Record summary
CVE-2008-1461 has a selected CVSS score of 7.6; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line. NOTE: it is unclear whether there are common handler configurations in which this argument is controlled by an attacker.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBXnView 1.92.1 - Command-Line Arguments Buffer OverflowExploitDB exploitby Sylvain THUALNot analyzed1 file
References
6click-internet.fr
http://www.click-internet.fr/index.php?cki=News&news=9 20080315 XNview 1.92.1 Long Filename Overflowmailing list
http://www.securityfocus.com/archive/1/489658/100/0/threaded 28259vdb entry
http://www.securityfocus.com/bid/28259 xnview-filename-bo(41245)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41245 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-1461