Impact
A FastStone Image Viewer component, the PCX decoder, contains an out‑of‑bounds read when processing certain PCX image files. The vulnerability allows a malicious user to craft a file that causes the application to read memory beyond the expected bounds, which could expose sensitive data or trigger a crash. The flaw is not limited to local execution; it can be triggered remotely by delivering the crafted image to a victim’s instance of the viewer.
Affected Systems
The issue affects FastStone Image Viewer versions up to 8.3. The specific function within the PCX decoder that is impacted is unknown from the disclosure. Users relying on this version or earlier for viewing PCX files are susceptible.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate risk, and no EPSS value is available, indicating limited publicly known exploitation activity. The vulnerability is listed outside the CISA KEV catalog. An attacker can supply a malicious PCX file to a remote user to trigger the out‑of‑bounds read. Because the read is untrusted, exploitation could be used to gain insight into the caller’s memory or to cause a denial of service.
OpenCVE Enrichment