Unrated severityNVD Advisory· Published Jan 2, 2020· Updated Aug 6, 2024
CVE-2013-3941
CVE-2013-3941
Description
Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- newsgroup.xnview.com/viewtopic.phpmitrex_refsource_MISC
- secunia.com/advisories/52101mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.