PT-2014-2916 · Google · Google Picasa
Publicado
2014-01-09
·
Atualizado
2014-04-25
·
CVE-2013-5359
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Google Picasa versions prior to 3.9.0 Build 137.69
Description
A stack-based buffer overflow issue exists, potentially allowing remote attackers to execute arbitrary code via a crafted RAW file. This can be demonstrated using a KDC file with a certain size.
Recommendations
For versions prior to 3.9.0 Build 137.69, update to version 3.9.0 Build 137.69 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted RAW files until the update is applied.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Google Picasa