VYPR
Unrated severityNVD Advisory· Published Jun 19, 2019· Updated Aug 4, 2024

CVE-2019-12895

CVE-2019-12895

Description

In Alternate Pic View 2.600, the Exception Handler Chain is Corrupted starting at PicViewer!PerfgrapFinalize+0x00000000000b916d.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Alternate Pic View 2.600 suffers from a corrupted exception handler chain leading to a crash via specially crafted files.

Vulnerability

In Alternate Pic View 2.600, the Exception Handler Chain is corrupted starting at PicViewer!PerfgrapFinalize+0x00000000000b916d. This vulnerability is triggered when the application processes a malformed image file, as demonstrated in reference [1] with fuzzed samples. The crash manifests as a write access violation or instruction pointer read violation.

Exploitation

An attacker needs to deliver a specially crafted file to a user running Alternate Pic View 2.600 and convince them to open it. No special network position or authentication is required beyond user interaction. The fuzzed samples in the reference cause the application to hit the corrupted exception handler chain, resulting in a crash.

Impact

Exploitation leads to a denial of service via application crash. The reference does not demonstrate code execution, only a user-mode write access violation, a read access violation at the instruction pointer, and a corrupted exception handler chain. The impact is limited to availability loss.

Mitigation

No official fix or patched version has been released as of the publication date. Users should avoid opening untrusted image files with Alternate Pic View 2.600. The software may be considered end-of-life; no update is available. Reference [1] does not indicate a KEV listing.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.