CVE-2013-5357
Estado: ModificadaAlta (7.5)—
Integer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a long TIFF tag that triggers a heap-based buffer overflow, as demonstrated using a Canon RAW CR2 file with a long TIFF StripByteCounts tag.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.30%
- Percentil entre todas las CVEs puntuadas: 83
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-119
Referencias
- http://secunia.com/advisories/55555
- http://secunia.com/secunia_research/2013-14/
- http://www.securitytracker.com/id/1029527
- https://support.google.com/picasa/answer/53209
- http://secunia.com/advisories/55555
- http://secunia.com/secunia_research/2013-14/
- http://www.securitytracker.com/id/1029527
- https://support.google.com/picasa/answer/53209
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-5357",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "PSIRT-CNA@flexerasoftware.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-01-09T00:55:02.927",
"references": [
{
"url": "http://secunia.com/advisories/55555",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://secunia.com/secunia_research/2013-14/",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.securitytracker.com/id/1029527",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://support.google.com/picasa/answer/53209",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://secunia.com/advisories/55555",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/secunia_research/2013-14/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1029527",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.google.com/picasa/answer/53209",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Integer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a long TIFF tag that triggers a heap-based buffer overflow, as demonstrated using a Canon RAW CR2 file with a long TIFF StripByteCounts tag."
},
{
"lang": "es",
"value": "Desbordamiento de enteros en Picasa3.exe en Google Picasa anterior a 3.9.0 Build 137.69 que permite a atacantes remotos ejecutar código arbitrario a través de una etiqueta TIFF grande que dispara un desbordamiento de búfer basado en la pila, como se ha demostrado mediante un archivo Canon RAW CR2 con la etiqueta TIFF StripByteCounts grande."
}
],
"lastModified": "2026-06-16T23:58:43.053",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:picasa:3.9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AD9C0A8-165B-4D92-B3F6-AC89982F7F79"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "PSIRT-CNA@flexerasoftware.com"
}