Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-28275

Опубликовано: 23 мар. 2022
Источник: debian
EPSS Низкий

Описание

A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jheadfixed1:3.06.0.1-2package

Примечания

  • https://github.com/Matthias-Wandel/jhead/commit/a50953a266583981b51a181c2fce73dad2ac5d7d (3.06.0.1)

  • https://github.com/Matthias-Wandel/jhead/issues/17

  • Crash in CLI tool, no security impact

EPSS

Процентиль: 22%
0.00071
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 4 года назад

A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.

CVSS3: 5.5
nvd
почти 4 года назад

A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.

CVSS3: 5.5
github
почти 4 года назад

A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.

EPSS

Процентиль: 22%
0.00071
Низкий