First published: Thu Jul 28 2011(Updated: )
Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Products | <=3.6_build_105.65 | |
Google Products | =3.5 | |
Google Products | =3.5_build_79.67 | |
Google Products | =3.5_build_79.69 | |
Google Products | =3.5_build_79.74 | |
Google Products | =3.5_build_79.81 | |
Google Products | =3.5_build_95.18 | |
Google Products | =3.6_build_95.25 | |
Google Products | =3.6_build_105.41 | |
Google Products | =3.6_build_105.61 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2747 is considered a critical vulnerability that allows remote code execution through crafted JPEG images.
To fix CVE-2011-2747, upgrade Google Picasa to version 3.6 Build 105.67 or later.
CVE-2011-2747 affects Google Picasa versions up to and including 3.6 Build 105.65.
CVE-2011-2747 can be exploited by attackers who send specially crafted JPEG image files to execute arbitrary code on the victim's machine.
Users of Google Picasa versions prior to 3.6 Build 105.67 are vulnerable to CVE-2011-2747.