|
|
|
|
| |
Credit:
The information has been provided by Secunia Research.
The original article can be found at: http://secunia.com/secunia_research/2008-24/
|
| |
Vulnerable Systems:
* XnView version 1.93.6 for Windows
* XnView version 1.70 for Linux and FreeBSD
* NConvert version 4.92
* GFL SDK version 2.82
Immune Systems:
* XnView version 1.94 beta1
The vulnerability is caused due to a boundary error when processing the "format" keyword of Sun TAAC files. This can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into viewing a specially crafted Sun TAAC file.
Successful exploitation allows execution of arbitrary code.
The vulnerability is confirmed in version 1.70 of XnView for Linux and FreeBSD, XnView 1.93.6 for Windows, GFL SDK 2.82, and NConvert 4.92. Other versions may also be affected.
Solution :
XnView:
The vulnerability is fixed in version 1.94 beta1.
NConvert and GFL SDK:
A fixed version is not currently available. Do not open untrusted Sun
TAAC files.
Time Table
28/05/2008 - Vendor notified.
29/05/2008 - Vendor response.
18/06/2008 - Vendor issues XnView 1.94 beta1.
20/06/2008 - Public disclosure.
CVE Information:
CVE-2008-2427
|
|
|
|
|