Vulnerabilities > CVE-2011-1338 - Unspecified vulnerability in Xnview
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN xnview
nessus
Summary
Untrusted search path vulnerability in XnView before 1.98.1 allows local users to gain privileges via a Trojan horse .exe file in a folder selected by the "Open containing folder" menu item.
Vulnerable Configurations
Nessus
NASL family | Windows |
NASL id | XNVIEW_1_98_1.NASL |
description | The version of XnView installed on the remote Windows host is earlier than 1.98.1. As such, it reportedly uses unsafe methods for determining how to load executables. Specifically, there is an issue with the file search path, which could result in the insecure loading of executables when using the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 55535 |
published | 2011-07-07 |
reporter | This script is Copyright (C) 2011-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/55535 |
title | XnView < 1.98.1 Insecure Executable Loading |
code |
|
References
- http://jvn.jp/en/jp/JVN17844633/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-000050
- http://secunia.com/advisories/45127
- http://www.osvdb.org/73619
- http://www.securityfocus.com/bid/48562
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68369
- http://jvn.jp/en/jp/JVN17844633/index.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68369
- http://www.securityfocus.com/bid/48562
- http://www.osvdb.org/73619
- http://secunia.com/advisories/45127
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-000050