A vulnerability affecting major image manipulation and viewing software (Adobe Creative Suite 2 and 3 products are affected among others) has been published. This seems to affect Xnview too in its handling of xpm format.
Question:
Although I believe this is going to be corrected very soon with a patch, I'm curious if there is a way to disable support for xpm format in xnview and thus hopefully avoid possible system compromise
More details:
http://secunia.com/advisories/24973/
xnview vulnerability: XPM File Handling Buffer Overflow
Moderators: helmut, XnTriq, xnview
Re: xnview vulnerability
Yes, i have fixed it in next version...Anonymous wrote:A vulnerability affecting major image manipulation and viewing software (Adobe Creative Suite 2 and 3 products are affected among others) has been published. This seems to affect Xnview too in its handling of xpm format.
Question:
Although I believe this is going to be corrected very soon with a patch, I'm curious if there is a way to disable support for xpm format in xnview and thus hopefully avoid possible system compromise
More details:
http://secunia.com/advisories/24973/
Pierre.
Thank you
Thank you for your fast reply, xnview! Can you estimate when is the next version going to be released ?
@ckit
I fiddled with the options and all I could find is a menu where I can check/uncheck file handling by xnview when a file type is accesed in Windows explorer, but this is based on file extension I believe; Somebody could craft a malicious file and change it's extension to a much wider used format and the extension filter may not work in this case.
@ckit
I fiddled with the options and all I could find is a menu where I can check/uncheck file handling by xnview when a file type is accesed in Windows explorer, but this is based on file extension I believe; Somebody could craft a malicious file and change it's extension to a much wider used format and the extension filter may not work in this case.
Re: Thank you
I hope to upload the version 1.90.4 in 2 weeksAnonymous wrote:Thank you for your fast reply, xnview! Can you estimate when is the next version going to be released ?
Pierre.
That's good.xnview wrote:I hope to upload the version 1.90.4 in 2 weeks
I've just added this one to the list of must fixes for the next release.
Re: Thank you
Thank you for your work.xnview wrote:I hope to upload the version 1.90.4 in 2 weeksAnonymous wrote:Thank you for your fast reply, xnview! Can you estimate when is the next version going to be released ?