First published: Mon Mar 28 2011(Updated: )
Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Google Products | <=3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0458 has a moderate severity rating due to its ability to allow local users to gain privileges.
To fix CVE-2011-0458, upgrade Google Picasa to version 3.8 or later.
Users of Google Picasa versions prior to 3.8 are affected by CVE-2011-0458.
CVE-2011-0458 is caused by an untrusted search path vulnerability in the Locate on Disk feature.
CVE-2011-0458 cannot be exploited remotely, as it requires local user access to execute a Trojan horse executable.