Vulnerabilities > CVE-2011-0458 - Unspecified vulnerability in Google Picasa 3.6
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN google
nessus
Summary
Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Windows |
NASL id | GOOGLE_PICASA_3_8.NASL |
description | The version of Google Picasa running on the remote host is earlier than 3.8. Such versions insecurely look in their current working directory when resolving DLL dependencies. Attackers may exploit the issue by placing a specially crafted DLL file and another file associated with the application in a location controlled by the attacker. When the associated file is launched, the attacker |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 52980 |
published | 2011-03-25 |
reporter | This script is Copyright (C) 2011-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/52980 |
title | Google Picasa < 3.8 Path Subversion Arbitrary DLL Injection Code Execution |
code |
|
Seebug
bulletinFamily | exploit |
description | CVE ID: CVE-2011-0458 Google Picasa一款可帮助您在计算机上立即找到、修改和共享所有图片的图象浏览器。 Google Picasa在实现上存在不安全库加载漏洞,远程攻击者可利用此漏洞控制用户系统。 此漏洞源于应用程序以不安全的方式加载库。可通过"Locate on Disk"功能诱使用户打开位于远程WebDAV或SMB共享上的某些文件加载任意库。 Google Picasa 3.x 厂商补丁: Google ------ 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: http://www.google.com |
id | SSV:20407 |
last seen | 2017-11-19 |
modified | 2011-03-29 |
published | 2011-03-29 |
reporter | Root |
title | Google Picasa 3.x 不安全库装载任意代码执行漏洞 |
References
- http://jvn.jp/en/jp/JVN99977321/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-000022
- http://osvdb.org/71281
- http://secunia.com/advisories/43853
- http://www.securityfocus.com/bid/47031
- http://www.vupen.com/english/advisories/2011/0766
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66295
- http://jvn.jp/en/jp/JVN99977321/index.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66295
- http://www.vupen.com/english/advisories/2011/0766
- http://www.securityfocus.com/bid/47031
- http://secunia.com/advisories/43853
- http://osvdb.org/71281
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-000022