Peaches Posted December 7, 2010 Report Share Posted December 7, 2010 </h5><h5>Google Earth Insecure Library Loading VulnerabilitySecunia Advisory SA42524 Release Date 2010-12-06Criticality level Highly critical DescriptionA vulnerability has been discovered in Google Earth, which can be exploited by malicious people to compromise a user's system.The vulnerability is caused due to the application loading libraries (e.g. wintab32.dll and quserex.dll) in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into e.g. opening a KMZ file located on a remote WebDAV or SMB share. Successful exploitation allows execution of arbitrary code. The vulnerability is confirmed in version 5.1.3533.1731. Other versions may also be affected. SolutionUpgrade to version 6.0. Provided and/or discovered byTaeho Kwon and Zhendong SuOriginal Advisory http://www.cs.ucdavis.edu/research/tech-reports/2010/CSE-2010-2.pdf http://secunia.com/advisories/42524/ Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.