This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Google Picasa vuln - update available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Google Picasa vuln - update available
- http://secunia.com/advisories/45293/
Release Date: 2011-07-20
Criticality level: Highly critical
Impact: System access
Where: From remote
Software: Google Picasa 3.x
… vulnerability is reported in version 3.6 Build 105.61 for Windows and prior.
Solution: Update to version 3.6 Build 105.67 or later…
- http://picasa.google.com/

- http://h-online.com/-1283347
21 July 2011

:ph34r:
FYI…

Google Picasa 136.17 …
- https://secunia.com/advisories/51652/
Release Date: 2013-03-20
Criticality level: Highly critical
Impact: System access
Where: From remote…
For more information: https://secunia.com/SA35515/
… vulnerabilities are confirmed in version 3.9.0 Build 136.09 for Windows and reported in versions prior to 3.9.0 Build 3.9.14.34 for Mac. Other versions may also be affected.
Solution: Update to a fixed version.
Original Advisory: http://support.google.com/picasa/answer/53209
Windows: Build 136.17 - March 14, 2012

:ph34r: :ph34r:

FYI…

Google Picasa 3.9.0 Build 137.69 released
- https://secunia.com/advisories/55555/
Release Date: 2013-12-20
Criticality: Highly Critical
Where: From remote
Impact: System access
CVE Reference(s): CVE-2013-5349, CVE-2013-5357, CVE-2013-5358, CVE-2013-5359
… vulnerabilities are confirmed in version 3.9.0 Build 136.20 running on Windows and reported in versions -prior- to 3.9.0 Build 137.69 running on Mac. Prior versions may also be affected.
Solution: Update to version 3.9.0 Build 137.69 or later.
Original Advisory: Google Picasa:
- https://support.google.com/picasa/answer/53209
Secunia Research:
- http://secunia.com/secunia_research/2013-14/

- http://www.securitytracker.com/id/1029527
CVE Reference: CVE-2013-5349, CVE-2013-5357, CVE-2013-5358, CVE-2013-5359
Dec 20 2013
Impact: Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 3.9.0 Build 136.20 for Windows; possibly other versions
Solution: The vendor has issued a fix (3.6 Build 137.69 for Windows, 3.9.137.119 for Mac).
The vendor's advisory is available at:
- https://support.google.com/picasa/answer/53209
 

:ph34r: :ph34r: