VYPR
Unrated severityNVD Advisory· Published Jun 30, 2019· Updated Aug 4, 2024

CVE-2019-13085

CVE-2019-13085

Description

XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

XnView Classic 2.48 is vulnerable to an out-of-bounds write during file processing, causing a user-mode write access violation.

Vulnerability

XnView Classic version 2.48.0.0 (x86) contains an out-of-bounds write (OOBW) vulnerability during file processing. The bug triggers a user-mode write access violation at address xnview+0x30ecfa [1]. The exact file type or parsing routine is not specified, but the crash occurs when opening a crafted file.

Exploitation

To exploit this vulnerability, an attacker must convince a user to open a malicious file in XnView Classic. No special privileges are needed, as the file can be delivered via email, web download, or other means. Upon opening the file, the out-of-bounds write causes a crash [1]. Successful exploitation may require additional knowledge of memory layout for code execution.

Impact

The immediate impact is a denial of service due to application crash. However, out-of-bounds writes can potentially be leveraged for arbitrary code execution, though no exploit code is provided in the reference [1]. The crash indicates memory corruption, which could be further exploited depending on the attacker's skill.

Mitigation

As of the CVE publication date (2019-06-30), no official patch was available. Users should update XnView Classic to a version newer than 2.48 if a fix exists. Until then, avoid opening untrusted files with XnView Classic. No workaround is documented in the reference [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.