nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-26236 CVE-2021-26236
HIGH
FastStone Image Viewer 7.5 - .cur BITMAPINFOHEADER 'BitCount' Stack Based Buffer Overflow (ASLR & DEP Bypass)
Record summary
CVE-2021-26236 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsing functionality (BITMAPINFOHEADER Structure, 'BitCount' file format field), that will end up corrupting the Structure Exception Handler (SEH). Attackers could exploit this issue to achieve code execution when a user opens or views a malformed/specially crafted CUR file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFastStone Image Viewer 7.5 - .cur BITMAPINFOHEADER 'BitCount' Stack Based Buffer Overflow (ASLR & DEP Bypass)ExploitDB exploitby Paolo StagnoNot analyzed1 file
References
4voidsec.com
https://voidsec.com/advisories/cve-2021-26236-faststone-image-viewer-v-7-5-stack-based-buffer-overflow voidsec.com
https://voidsec.com/fuzzing-faststone-image-viewer-cve-2021-26236 exploit-db.com
https://www.exploit-db.com/exploits/49660