PT-2007-3120 · Faststone · Faststone Image Viewer
Publicado
2007-03-30
·
Atualizado
2018-10-16
·
CVE-2007-1764
CVSS v2.0
6.0
Média
| Vetor | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
FastStone Image Viewer version 2.8
Description:
The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a crafted JPG image. This can be achieved when a user assists the attacker, for example, by opening the malicious image.
Recommendations:
For FastStone Image Viewer version 2.8, consider avoiding the use of JPG images from untrusted sources until a patch is available. As a temporary workaround, restrict the use of the image viewing functionality to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Faststone Image Viewer