Title : XnView Slideshow "FontName" Parameter Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-1044 CVE ID : CVE-2008-0069
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-31
Technical Description
A vulnerability has been identified in XnView, which could be exploited by attackers to cause a denial of service or compromise an affected system. This issue is caused by a buffer overflow error when processing slideshow (*.sld) files with an overly long "FontName" parameter, which could be exploited by attackers to crash a vulnerable application or execute arbitrary commands by tricking a user into opening a specially crafted file.