Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-6612

Опубликовано: 04 фев. 2018
Источник: debian

Описание

An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-service attack or unspecified other impact.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jheadfixed1:3.00-6package

Примечания

  • https://anonscm.debian.org/git/collab-maint/jhead.git/diff/debian/patches/0008-heap-buffer-overflow.patch?id=01f09ab772d0d341cdc1326490dd2aa5aa2a7784

  • Crash in CLI tool, no security impact

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 8 лет назад

An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-service attack or unspecified other impact.

CVSS3: 5.5
nvd
около 8 лет назад

An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-service attack or unspecified other impact.

suse-cvrf
почти 8 лет назад

Security update for jhead

CVSS3: 5.5
github
больше 3 лет назад

An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-service attack or unspecified other impact.

suse-cvrf
больше 4 лет назад

Security update for jhead