Integer Overflow Vulnerability in Google Picasa
CVE-2013-5357

Currently unrated

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
9 January 2014

Summary

An integer overflow vulnerability exists in the Picasa3.exe component of Google Picasa, specifically affecting versions prior to 3.9.0 Build 137.69. This flaw allows remote attackers to exploit a crafted TIFF file, particularly one with extended StripByteCounts tags, to induce a heap-based buffer overflow. When successfully exploited, it can lead to arbitrary code execution on the targeted system, creating a significant security risk for users.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.