vendor:
Google Earth
by:
JAAScois
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Google Earth
Affected Version From: v4.0.2091(beta)
Affected Version To: v4.0.2091(beta)
Patch Exists: YES
Related CWE: N/A
CPE: a:google:google_earth
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Google Earth (kml & kmz files) buffer overflow
Google Earth is prone to a buffer-overflow vulnerability because the application fails to properly verify the size of user-supplied data before copying it into an insufficiently sized process buffer. This issue allows remote attackers to execute arbitrary machine code in the context of the user running the affected application. Failed exploit attempts will likely crash applications, denying service to legitimate users.
Mitigation:
Update to the latest version of Google Earth