PT-2017-18559 · Ijg+1 · Libjpeg+1
Published
2017-07-05
·
Updated
2021-03-24
·
CVE-2017-8826
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FastStone Image Viewer version 6.2
Description
The issue is related to a "User Mode Write AV" problem, possibly connected to the
jpeg mem term function in jmemnobs.c in libjpeg. This can be triggered by a malformed JPEG file that is mishandled by FSViewer.exe, potentially allowing attackers to exploit it for DoS (Access Violation) or other unspecified impacts.Recommendations
For FastStone Image Viewer version 6.2, consider avoiding the use of malformed JPEG files until a patch is available. As a temporary workaround, restricting the handling of JPEG files by
FSViewer.exe may help minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Faststone Image Viewer
Libjpeg