Lucene search

K
cveJpcertCVE-2011-0458
HistoryMar 28, 2011 - 4:55 p.m.

CVE-2011-0458

2011-03-2816:55:04
jpcert
web.nvd.nist.gov
33
cve
2011
0458
untrusted search path
vulnerability
google picasa
privileges
trojan horse
executable file

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0

Percentile

5.1%

Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory.

Affected configurations

Nvd
Node
googlepicasaRange3.6
VendorProductVersionCPE
googlepicasa*cpe:2.3:a:google:picasa:*:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0

Percentile

5.1%