首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Google Picasa 3.5 Local DoS Buffer Overflow
来源:vfocus.net 作者:Connection 发布时间:2009-12-17  

Connection of the HackTalk team recently found a buffer overflow in the Picasa software by Google.  Below is the write up.

Pentest Information:
====================
Connection has discovered a Buffer Overflow in Picasa 3.5 created by Google.
An attacker is able to overflow the EAX register by creating a text slide with a large block of text.

Details
=======
Tested on OS: Windows XP & Windows Vista
Tested with Software: Debugger & Picasa 3.5

Vulnerable Products: Picasa
Affected Versions: 3.5
Vulnerability Type: Buffer Overflow
Security-Risk: Low

Vendor-URL: http://picasa.google.com
Preview-URL:

Vendor-Status: Uninformed
Patch/Fix-Status: Fixed version not released
Advisory-Status: Published | 29.09.2009

Advisory-URL:
Report-URL:

Introduction:
=============
Picasa is free photo editing software from Google that makes your pictures look great.
Sharing your best photos with friends and family is as easy as pressing a button! ss.

(from the vendors homepage: http://picasa.google.com)

More Details:
=============
Due to the lack of input validation, an attacker is able to overwrite the ECX register and crash the program.

Proof of Concept:
=================
Open up Picasa and go to the movie creator. Add a new text slide and input 45440 characters. This will cause the program to crash. The following the the register dump from OllyDBG.

EAX 04875910 ASCII “AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
ECX 0000007D
EDX 00000000
EBX 049364D0 ASCII “AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
ESP 00129C1C
EBP 00129C24
ESI 04939B50 ASCII “AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
EDI 04878F90 ASCII “AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA”
EIP 0098C13E Picasa3.0098C13E
C 0  ES 0023 32bit 0(FFFFFFFF)
P 1  CS 001B 32bit 0(FFFFFFFF)
A 0  SS 0023 32bit 0(FFFFFFFF)
Z 0  DS 0023 32bit 0(FFFFFFFF)
S 0  FS 003B 32bit 7FFDF000(FFF)
T 0  GS 0000 NULL
D 0
O 0  LastErr ERROR_SUCCESS (00000000)
EFL 00010206 (NO,NB,NE,A,NS,PE,GE,G)
ST0 empty 23.500000000000000000
ST1 empty 19.000000000000000000
ST2 empty 19.000000000000000000
ST3 empty 0.0
ST4 empty 0.0
ST5 empty 1.0000000000000000000
ST6 empty 0.0
ST7 empty 0.0
3 2 1 0      E S P U O Z D I
FST 0020  Cond 0 0 0 0  Err 0 0 1 0 0 0 0 0  (GT)
FCW 027F  Prec NEAR,53  Mask    1 1 1 1 1 1

Security Risk:
==============
An attacker may crash Picasa by inputting a large block of text into a slide in the slideshow maker function of Picasa. The security risk is estimated as low.

Author:
=======
The Author & Writer is a part of the HackTalk team.
~Connection


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Monkey HTTP Daemon < 0.9.3 Den
·VideoCache 1.9.2 vccleaner roo
·Adobe Multimeda Doc.media.newP
·Cisco ASA <= 8.x VPN SSL modul
·3Com OfficeConnect ADSL Wirele
·win xp sp2 PEB ISbeingdebugged
·TFTP SERVER Buffer Overflow re
·Savant Web Server 3.1 Remote B
·Mozilla Firefox Location Bar S
·RM Downloader 3.0.2.1(.M3U Fil
·PlayMeNow Malformed M3U Playli
·PHP 5.2.12/5.3.1 symlink() ope
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved