CVE-2011-2747: Code Injection
Published Jul 28, 2011
·Updated
Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file.
Affected Software
10 affected components
Google Picasa<=3.6_build_105.65
Google Picasa=3.5
Google Picasa=3.5_build_79.67
Google Picasa=3.5_build_79.69
Google Picasa=3.5_build_79.74
Google Picasa=3.5_build_79.81
Google Picasa=3.5_build_95.18
Google Picasa=3.6_build_95.25
Google Picasa=3.6_build_105.41
Google Picasa=3.6_build_105.61
Event History
Jul 28, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2747?
CVE-2011-2747 is considered a critical vulnerability that allows remote code execution through crafted JPEG images.
2
How do I fix CVE-2011-2747?
To fix CVE-2011-2747, upgrade Google Picasa to version 3.6 Build 105.67 or later.
3
What versions of Google Picasa are affected by CVE-2011-2747?
CVE-2011-2747 affects Google Picasa versions up to and including 3.6 Build 105.65.
4
What type of attacks can exploit CVE-2011-2747?
CVE-2011-2747 can be exploited by attackers who send specially crafted JPEG image files to execute arbitrary code on the victim's machine.
5
Who is vulnerable to CVE-2011-2747?
Users of Google Picasa versions prior to 3.6 Build 105.67 are vulnerable to CVE-2011-2747.