Junglewise Threat Intelligence

CVE-2026-30041: FastStone Image Viewer integer overflow in PSD parser

CVE-2026-30041 · Severity: info · CVSS 7.8 · Published 2026-06-26

Executive brief

FastStone Image Viewer, a popular tool for managing and editing photos, contains a security flaw in how it processes PSD (Adobe Photoshop) files. By tricking a user into opening a specially crafted image file, an attacker could crash the application or potentially take control of the computer to run unauthorized commands. This risk is particularly high for users who frequently download images from untrusted sources.

Technical details

An integer overflow vulnerability exists within the PSD file parser of FastStone Image Viewer (versions 8.3 and earlier). The flaw stems from insufficient validation of the 'height' value within PSD metadata, which leads to a heap-based buffer overflow during memory allocation and data processing. An attacker can exploit this by providing a maliciously crafted PSD file; if a user opens the file, the attacker may overwrite the instruction pointer (EIP) to achieve arbitrary code execution or cause the application to crash. As of the advisory date, the vendor has not released a patch, and users are advised to use restricted accounts and avoid opening untrusted PSD files.

Affected products

  • FastStone Image Viewer 8.3 and earlier

Timeline

  • 2026-05-12: other: Vendor notified
  • 2026-06-22: disclosed: Vulnerability disclosed by CERT/CC
  • 2026-06-26: advisory: CVE published in NVD

References

Related threats