CVE-2026-101205: FastStone Image Viewer PCX Decoder out-of-bounds
A vulnerability was determined in FastStone Image Viewer up to 8.3. This impacts an unknown function of the component PCX Decoder. This manipulation causes out-of-bounds read. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker needs to induce a user to process a malicious PCX image with FastStone Image Viewer. No attacker privileges are required, but user interaction is required.
Which installations may be affected?
FastStone Image Viewer versions up to and including 8.3 are identified as affected. The available information does not state whether any particular default file-association or viewing configuration is required.
What can be done if an update is not available?
Avoid opening PCX files from untrusted sources in FastStone Image Viewer. Limit access to untrusted image attachments and downloads until a vendor response or remediation is available.
How can exposure be assessed?
Check whether FastStone Image Viewer is installed and whether its version is 8.3 or earlier. Also identify workflows in which users open PCX images received from external or untrusted sources.