Vulnerability Description
Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, leading to a heap-based buffer overflow.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xnview | Xnview | <= 1.97.1 |
Related Weaknesses (CWE)
References
- http://newsgroup.xnview.com/viewtopic.php?f=35&t=19469Patch
- http://secunia.com/secunia_research/2009-60/
- http://www.osvdb.org/62829
- http://www.securityfocus.com/archive/1/509999/100/0/threaded
- http://www.securityfocus.com/bid/38629
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56802
- http://newsgroup.xnview.com/viewtopic.php?f=35&t=19469Patch
- http://secunia.com/secunia_research/2009-60/
- http://www.osvdb.org/62829
- http://www.securityfocus.com/archive/1/509999/100/0/threaded
- http://www.securityfocus.com/bid/38629
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56802
FAQ
What is CVE-2009-4001?
CVE-2009-4001 is a vulnerability with a CVSS score of 9.3 (HIGH). Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, leading to a heap-based buffer overflow.
How severe is CVE-2009-4001?
CVE-2009-4001 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4001?
Check the references section above for vendor advisories and patch information. Affected products include: Xnview Xnview.