CVE-2026-101202: FastStone Image Viewer TGA Image out-of-bounds write
A flaw has been found in FastStone Image Viewer up to 8.3. The affected element is an unknown function of the component TGA Image Handler. Executing a manipulation can lead to out-of-bounds write. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running FastStone Image Viewer version 8.3 or earlier are affected, specifically through its TGA image handling component. The attack can be launched remotely, but exploitation requires user interaction.
What does an attacker need to exploit it?
An attacker needs to induce a user to process a manipulated TGA image with the affected application. No attacker privileges are required, and the reported attack complexity is low.
What is the potential impact?
Successful exploitation can cause an out-of-bounds write and may affect the confidentiality, integrity, and availability of the affected system at low impact levels.
Is a vendor fix available?
The available information does not identify a fixed version or vendor-provided remediation. The vendor was contacted before disclosure but did not respond.