Skip to main content

Google Picasa Multiple Vulnerabilities

Last Update Date: 21 Mar 2013 09:53 Release Date: 21 Mar 2013 3473 Views

RISK: Medium Risk

TYPE: Clients - Graphics & Design

TYPE: Graphics & Design

Multiple vulnerabilities have been identified in Google Picasa, which can be exploited by malicious people to compromise a user's system.

  1. A sign extension error when processing the color table of a BMP image can be exploited to cause a heap-based buffer overflow via a BMP image with a specially crafted "biBitCount" field.
  2. The application bundles a vulnerable version of LibTIFF.

Successful exploitation may allow execution of arbitrary code.


Impact

  • Remote Code Execution

System / Technologies affected

  • Google Picasa 3.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to a fixed version.

Vulnerability Identifier

  • No CVE information is available

Source


Related Link