CVE-2017-6078: Input Validation
Published Feb 21, 2017
·Updated
FastStone MaxView 3.0 and 3.1 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with a crafted biSize field in the BITMAPINFOHEADER section.
Affected Software
2 affected components
FastStone MaxView=3.0
FastStone MaxView=3.1
Event History
Feb 21, 2017
CVE Published
via MITRE·07:46 AM
Data Sourced
via MITRE·07:46 AM
Description
Data Sourced
via NVD·07:59 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6078?
CVE-2017-6078 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-6078?
To fix CVE-2017-6078, users should update to a version of FastStone MaxView that addresses the vulnerability.
3
Which versions of FastStone MaxView are affected by CVE-2017-6078?
CVE-2017-6078 affects FastStone MaxView versions 3.0 and 3.1.
4
What type of attack does CVE-2017-6078 involve?
CVE-2017-6078 involves user-assisted attacks that can lead to an application crash when processing a malformed BMP image.
5
Is CVE-2017-6078 a remote or local vulnerability?
CVE-2017-6078 is considered a local vulnerability requiring user interaction to exploit.