PT-2021-16976 · Faststone · Faststone Image Viewer

Voidsec

·

Published

2021-03-18

·

Updated

2021-03-22

·

CVE-2021-26235

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FastStone Image Viewer versions prior to 7.6
Description The issue arises when a user opens or views a malformed CUR file, which is mishandled by FSViewer.exe, leading to a user mode write access violation. This could potentially be exploited for a Denial of Service (DoS) or possibly to achieve code execution.
Recommendations For FastStone Image Viewer versions prior to 7.6, update to version 7.6 or later to resolve the issue. As a temporary workaround, consider avoiding the use of malformed CUR files until a patch is applied. Restrict access to untrusted image files to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26235

Affected Products

Faststone Image Viewer