A vulnerability affecting major image manipulation and viewing software (Adobe Creative Suite 2 and 3 products are affected among others) has been published. This seems to affect Xnview too in its handling of xpm format.
Question:
Although I believe this is going to be corrected very soon with a patch, I'm curious if there is a way to disable support for xpm format in xnview and thus hopefully avoid possible system compromise
More details:
http://secunia.com/advisories/24973/
xnview vulnerability: XPM File Handling Buffer Overflow
Moderator: xnview
-
ckit
- XnThusiast
- Posts: 2586
- Joined: Tue Feb 17, 2004 1:11 am
- Location: QLD, Australia
-
xnview
- Author of XnView
- Posts: 47249
- Joined: Mon Oct 13, 2003 7:31 am
- Location: France
Re: xnview vulnerability
Yes, i have fixed it in next version...Anonymous wrote:A vulnerability affecting major image manipulation and viewing software (Adobe Creative Suite 2 and 3 products are affected among others) has been published. This seems to affect Xnview too in its handling of xpm format.
Question:
Although I believe this is going to be corrected very soon with a patch, I'm curious if there is a way to disable support for xpm format in xnview and thus hopefully avoid possible system compromise
More details:
http://secunia.com/advisories/24973/
Pierre.
-
Guest
Thank you
Thank you for your fast reply, xnview! Can you estimate when is the next version going to be released ?
@ckit
I fiddled with the options and all I could find is a menu where I can check/uncheck file handling by xnview when a file type is accesed in Windows explorer, but this is based on file extension I believe; Somebody could craft a malicious file and change it's extension to a much wider used format and the extension filter may not work in this case.
@ckit
I fiddled with the options and all I could find is a menu where I can check/uncheck file handling by xnview when a file type is accesed in Windows explorer, but this is based on file extension I believe; Somebody could craft a malicious file and change it's extension to a much wider used format and the extension filter may not work in this case.
-
helmut
- Posts: 8704
- Joined: Sun Oct 12, 2003 6:47 pm
- Location: Frankfurt, Germany
-
xnview
- Author of XnView
- Posts: 47249
- Joined: Mon Oct 13, 2003 7:31 am
- Location: France
Re: Thank you
I hope to upload the version 1.90.4 in 2 weeksAnonymous wrote:Thank you for your fast reply, xnview! Can you estimate when is the next version going to be released ?
Pierre.
-
helmut
- Posts: 8704
- Joined: Sun Oct 12, 2003 6:47 pm
- Location: Frankfurt, Germany
That's good.xnview wrote:I hope to upload the version 1.90.4 in 2 weeks
I've just added this one to the list of must fixes for the next release.
-
Guest
Re: Thank you
Thank you for your work.xnview wrote:I hope to upload the version 1.90.4 in 2 weeksAnonymous wrote:Thank you for your fast reply, xnview! Can you estimate when is the next version going to be released ?