Google Picasa JPEG Image Processing Remote Code Executiion Vulnerability
BID:48725
Info
Google Picasa JPEG Image Processing Remote Code Executiion Vulnerability
| Bugtraq ID: | 48725 |
| Class: | Unknown |
| CVE: |
CVE-2011-2747 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2011 12:00AM |
| Updated: | Jul 19 2011 12:00AM |
| Credit: | David Weston of Microsoft |
| Vulnerable: |
Google Picasa 3.6 Build 105.61 |
| Not Vulnerable: |
Google Picasa 3.6 Build 105.67 Google Picasa 3.6 B |
Discussion
Google Picasa JPEG Image Processing Remote Code Executiion Vulnerability
Google Picasa is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts will result in a denial-of-service condition.
Google Picasa is prone to a remote code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Google Picasa JPEG Image Processing Remote Code Executiion Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Google Picasa JPEG Image Processing Remote Code Executiion Vulnerability
Solution:
Reportedly, the vendor has released patches and Picasa 3.6 Build 105.41 to address this issue, but Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the vendor has released patches and Picasa 3.6 Build 105.41 to address this issue, but Symantec has not confirmed this. Please contact the vendor for more information.
References
Google Picasa JPEG Image Processing Remote Code Executiion Vulnerability
References:
References:
- Microsoft Vulnerability Research Advisory MSVR11-008 (Microsoft)
- Picasa Homepage (Google)