Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 360539 (CVE-2011-0458) - <media-gfx/picasa-3.8: Insecure Library Loading Vulnerability (CVE-2011-0458)
Summary: <media-gfx/picasa-3.8: Insecure Library Loading Vulnerability (CVE-2011-0458)
Status: RESOLVED WONTFIX
Alias: CVE-2011-0458
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: http://secunia.com/advisories/43853/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-03-26 12:09 UTC by Paweł Hajdan, Jr. (RETIRED)
Modified: 2013-03-27 13:22 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-03-26 12:09:23 UTC
A vulnerability has been reported in Google Picasa, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to the application loading libraries in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening certain files located on a remote WebDAV or SMB share via the "Locate on Disk" functionality.

Successful exploitation may allow the execution of arbitrary code.


Solution
Update to version 3.8.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2011-06-24 00:31:13 UTC
CVE-2011-0458 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0458):
  Untrusted search path vulnerability in the Locate on Disk feature in Google
  Picasa before 3.8 allows local users to gain privileges via a Trojan horse
  executable file in the current working directory.
Comment 2 Vlastimil Babka (Caster) (RETIRED) gentoo-dev 2011-10-23 21:06:34 UTC
Uh I missed this completely.
Anyway, there is no 3.8 version for linux, and I am not sure if the bug applies to linux anyway.
Comment 3 Dion Moult (RETIRED) gentoo-dev 2013-03-27 13:22:09 UTC
Package removed. See bug #434390.