Vulnerability Description
Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Picasa | <= 3.6_build_105.65 |
Related Weaknesses (CWE)
References
- http://osvdb.org/73980
- http://picasa.google.com/support/bin/static.py?hl=en&page=release_notes.cs&from=
- http://secunia.com/advisories/45293Vendor Advisory
- http://www.microsoft.com/technet/security/advisory/msvr11-008.mspx
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68735
- http://osvdb.org/73980
- http://picasa.google.com/support/bin/static.py?hl=en&page=release_notes.cs&from=
- http://secunia.com/advisories/45293Vendor Advisory
- http://www.microsoft.com/technet/security/advisory/msvr11-008.mspx
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68735
FAQ
What is CVE-2011-2747?
CVE-2011-2747 is a vulnerability with a CVSS score of 9.3 (HIGH). Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file.
How severe is CVE-2011-2747?
CVE-2011-2747 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-2747?
Check the references section above for vendor advisories and patch information. Affected products include: Google Picasa.