9.3
CVSSv2

CVE-2008-2427

Published: 24/06/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote malicious users to execute arbitrary code via a crafted format keyword in a Sun TAAC file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pagesperso-orange gfl sdk 2.82

pagesperso-orange nconvert 4.92

pagesperso-orange xnview 1.93.6

pagesperso-orange xnview 1.70

Exploits

#include <stdioh> #include <stdlibh> /* XnView 1936 for Windows taac buffer overflow proof of concept The vulnerability is caused due to a boundary error when processing the "format" keyword of Sun TAAC files This can be exploited to cause a stack-based buffer overflow by eg tricking a user into viewing a specially crafted S ...