PT-2017-18559 · Ijg+1 · Libjpeg+1
Publicado
2017-07-05
·
Atualizado
2021-03-24
·
CVE-2017-8826
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FastStone Image Viewer version 6.2
Description
The issue is related to a "User Mode Write AV" problem, possibly connected to the
jpeg mem term function in jmemnobs.c in libjpeg. This can be triggered by a malformed JPEG file that is mishandled by FSViewer.exe, potentially allowing attackers to exploit it for DoS (Access Violation) or other unspecified impacts.Recommendations
For FastStone Image Viewer version 6.2, consider avoiding the use of malformed JPEG files until a patch is available. As a temporary workaround, restricting the handling of JPEG files by
FSViewer.exe may help minimize the risk of exploitation.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Faststone Image Viewer
Libjpeg