Vulnerabilities > CVE-2020-23886 - Out-of-bounds Write vulnerability in Xnview MP
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted pict file. Related to a User Mode Write AV starting at ntdll!RtlpLowFragHeapFree.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Common Weakness Enumeration (CWE)
References
- https://cwe.mitre.org/data/definitions/122.html
- https://cwe.mitre.org/data/definitions/122.html
- https://github.com/Aurorainfinity/vulnerabilities/tree/master/xnviewmp
- https://github.com/Aurorainfinity/vulnerabilities/tree/master/xnviewmp
- https://www.xnview.com/en/xnviewmp/
- https://www.xnview.com/en/xnviewmp/