Integer Overflow Vulnerability in Google Picasa
CVE-2013-5357
Currently unrated
Summary
An integer overflow vulnerability exists in the Picasa3.exe component of Google Picasa, specifically affecting versions prior to 3.9.0 Build 137.69. This flaw allows remote attackers to exploit a crafted TIFF file, particularly one with extended StripByteCounts tags, to induce a heap-based buffer overflow. When successfully exploited, it can lead to arbitrary code execution on the targeted system, creating a significant security risk for users.
References
Timeline
Vulnerability published
Vulnerability Reserved