Google Picasa Heap Buffer Overflow Vulnerability (CVE-2015-8096)
Google Picasa Heap Buffer Overflow Vulnerability (CVE-2015-8096)
Release date:
Updated on:
Affected Systems:
Google Picasa 3.9.140 Build 248
Google Picasa 3.9.140 Build 239
Description:
CVE (CAN) ID: CVE-2015-8096
Picasa is an application for organizing and editing digital photos.
An integer overflow vulnerability exists in Google Picasa 3.9.140 Build 239 and Build 248. Remote attackers can exploit this vulnerability to execute arbitrary code after triggering a heap buffer overflow with Phase 1 0x412 tag-related data.
<* Source: Hossein Lotfi
Link: http://www.securityfocus.com/archive/1/archive/1/536761/100/0/threaded
*>
Suggestion:
Vendor patch:
Google
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Refer:
Http://secunia.com/secunia_research/2015-03/
Install Picasa 3.9 in Linux and fix GOOGLE logon Problems
This article permanently updates the link address: