Improper input validation - CVE-2017-10748

 

Improper input validation - CVE-2017-10748

Published: October 6, 2017 / Updated: October 16, 2017


Vulnerability identifier: #VU8717
CSH Severity: Medium
CVSS v4.0:
CVE-ID: CVE-2017-10748
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor:
Affected software:

Detailed vulnerability description

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000022bf8d."

How to mitigate CVE-2017-10748


Sources