Impact
FastStone Image Viewer contains an out-of-bounds read flaw in the TGA Image Handler within FSViewer.exe. The vulnerability arises when processing a malicious TGA file, allowing an attacker to read memory beyond the intended buffer. This can expose sensitive data stored on the system or within the process, potentially leading to confidentiality loss, but it does not provide direct code execution or system compromise. The flaw is exploitable through remote means, meaning a malicious user can supply a crafted TGA image over the network, such as via a remote file server or an email attachment, and have the vulnerable application read it without local interaction.
Affected Systems
The vulnerability affects FastStone Image Viewer versions up to and including 8.3. Earlier releases prior to 8.3 are not listed as affected, and any later versions do not contain the flaw as per available information. The issue resides specifically in the FSViewer.exe component handling TGA image files.
Risk and Exploitability
The CVSS score for this flaw is 5.3, placing it in the moderate severity range. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the vulnerability remotely by delivering a specially crafted TGA image to a victim running the affected version of the viewer. No additional authentication or privilege escalation is mentioned, suggesting the attack requires only that the application be run. The potential impact is limited to information disclosure and does not extend to corruption or denial of service.
OpenCVE Enrichment