VulnerabilityModified
CVE-2011-0458
Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.
MEDIUM 6.9EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Affected
- google/picasa
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN99977321/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-000022
- http://osvdb.org/71281
- http://secunia.com/advisories/43853Vendor Advisory
- http://www.securityfocus.com/bid/47031
- http://www.vupen.com/english/advisories/2011/0766Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66295
- http://jvn.jp/en/jp/JVN99977321/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-000022
- http://osvdb.org/71281
- http://secunia.com/advisories/43853Vendor Advisory
- http://www.securityfocus.com/bid/47031
- http://www.vupen.com/english/advisories/2011/0766Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66295
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.