PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-6078 Faststone CVE debrief

CVE-2017-6078 is a user-assisted denial-of-service issue affecting FastStone MaxView 3.0 and 3.1. According to the official CVE/NVD records, a malformed BMP image with a crafted biSize field in the BITMAPINFOHEADER section can cause the application to crash. The issue is rated medium severity and requires user interaction, so the main risk is instability or workflow interruption rather than code execution or data theft.

Vendor
Faststone
Product
Maxview
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-21
Original CVE updated
2026-05-13
Advisory published
2017-02-21
Advisory updated
2026-05-13

Who should care

Organizations or individuals still using FastStone MaxView 3.0 or 3.1, especially in environments where users may open untrusted image files. Security teams supporting help desks, desktop fleets, or kiosk-style endpoints should also care because the trigger is user-assisted and local.

Technical summary

NVD maps CVE-2017-6078 to FastStone MaxView 3.0 and 3.1 and describes the flaw as a malformed BMP parsing problem. The crafted input targets the BITMAPINFOHEADER biSize field and can make the application crash. The CVSS vector provided by NVD is AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, which reflects a local, user-interaction-dependent availability impact. NVD also lists CWE-20 (Improper Input Validation).

Defensive priority

Medium. The issue is not remotely exploitable from the supplied record, but it can still disrupt users who open attacker-supplied BMP files in affected versions.

Recommended defensive actions

  • Identify any systems running FastStone MaxView 3.0 or 3.1 and treat them as affected.
  • Limit exposure to untrusted BMP files, especially in email, downloads, shared folders, and removable-media workflows.
  • Where practical, open untrusted images in a sandboxed or isolated viewer instead of the affected application.
  • Monitor for application crashes tied to BMP parsing and use those events as indicators of exposure.
  • If the product must remain deployed, apply local hardening and application-control measures to reduce interaction with untrusted content.

Evidence notes

The debrief is based on the supplied CVE description, the NVD record, and the linked third-party advisory reference. Official NVD data lists affected versions 3.0 and 3.1, the malformed BMP/biSize crash condition, CVSS 3.0 vector AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, and CWE-20. The supplied record does not include a vendor patch notice or a CISA KEV entry.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-6078 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-6078

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-6078 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6078

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.