Out-of-Bounds Write Vulnerability in FastStone Image Viewer by FastStone Soft
CVE-2020-35845

7.8HIGH

Key Information:

Vendor

Faststone

Vendor
CVE Published:
26 January 2021

What is CVE-2020-35845?

FastStone Image Viewer 7.5 is vulnerable to an out-of-bounds write issue, which can be triggered by a specially crafted image file. This vulnerability allows attackers to potentially execute arbitrary code or cause a denial of service. The flaw occurs at the FSViewer.exe+0x96cf address, posing serious security risks to users of the software. It's crucial for users to update to newer versions or implement protective measures against this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.