Google Picasa Insecure Library Loading Arbitrary Code Execution Vulnerability
BID:47031
Info
Google Picasa Insecure Library Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 47031 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-0458 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 25 2011 12:00AM |
| Updated: | Mar 25 2011 12:00AM |
| Credit: | Makoto Shiotsuki via JPCERT/CC |
| Vulnerable: |
Google Picasa 3.6 |
| Not Vulnerable: |
Google Picasa 3.8 |
Discussion
Google Picasa Insecure Library Loading Arbitrary Code Execution Vulnerability
Google Picasa is prone to a vulnerability that lets attackers execute arbitrary code.
A successful exploit can allow the attacker to execute arbitrary code in the context of the user running the affected application.
Google Picasa versions prior to 3.8 are vulnerable.
Google Picasa is prone to a vulnerability that lets attackers execute arbitrary code.
A successful exploit can allow the attacker to execute arbitrary code in the context of the user running the affected application.
Google Picasa versions prior to 3.8 are vulnerable.
Exploit / POC
Google Picasa Insecure Library Loading Arbitrary Code Execution Vulnerability
Attackers can exploit the issue using standard commands.
Attackers can exploit the issue using standard commands.
Solution / Fix
Google Picasa Insecure Library Loading Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Google Picasa Insecure Library Loading Arbitrary Code Execution Vulnerability
References:
References: