Description
A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe of the component TGA Image Handler. The manipulation results in out-of-bounds read. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure from out-of-bounds read
Action: Assess Impact
AI Analysis

Impact

FastStone Image Viewer contains an out-of-bounds read flaw in the TGA Image Handler within FSViewer.exe. The vulnerability arises when processing a malicious TGA file, allowing an attacker to read memory beyond the intended buffer. This can expose sensitive data stored on the system or within the process, potentially leading to confidentiality loss, but it does not provide direct code execution or system compromise. The flaw is exploitable through remote means, meaning a malicious user can supply a crafted TGA image over the network, such as via a remote file server or an email attachment, and have the vulnerable application read it without local interaction.

Affected Systems

The vulnerability affects FastStone Image Viewer versions up to and including 8.3. Earlier releases prior to 8.3 are not listed as affected, and any later versions do not contain the flaw as per available information. The issue resides specifically in the FSViewer.exe component handling TGA image files.

Risk and Exploitability

The CVSS score for this flaw is 5.3, placing it in the moderate severity range. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the vulnerability remotely by delivering a specially crafted TGA image to a victim running the affected version of the viewer. No additional authentication or privilege escalation is mentioned, suggesting the attack requires only that the application be run. The potential impact is limited to information disclosure and does not extend to corruption or denial of service.

Generated by OpenCVE AI on September 28, 2026 at 23:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update FastStone Image Viewer to the latest available version that contains a fix; if a patch is not yet released, check the vendor’s website for updates or notification of a future fix.
  • Disallow or quarantine TGA images from untrusted sources, or disable TGA support entirely if the application allows it, to prevent the vulnerable code path from being invoked.
  • Replace FastStone Image Viewer with a trusted image viewer that does not rely on the exposed TGA handler until the vendor releases a remediation.

Generated by OpenCVE AI on September 28, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe of the component TGA Image Handler. The manipulation results in out-of-bounds read. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Title FastStone Image Viewer TGA Image FSViewer.exe out-of-bounds
First Time appeared Faststone
Faststone image Viewer
Weaknesses CWE-119
CWE-125
CPEs cpe:2.3:a:faststone:image_viewer:*:*:*:*:*:*:*:*
Vendors & Products Faststone
Faststone image Viewer
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Faststone Image Viewer
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T21:45:07.824Z

Reserved: 2026-09-28T09:39:57.518Z

Link: CVE-2026-101204

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T22:17:31.617

Modified: 2026-09-28T22:17:31.617

Link: CVE-2026-101204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T23:45:08Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read