Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-2824

Опубликовано: 22 мар. 2024
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function PrintFormatNumber of the file exif.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257711.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jheadunfixedpackage

Примечания

  • Crash in CLI tool, no security impact

  • https://github.com/Matthias-Wandel/jhead/issues/84

  • Fixed by: https://github.com/Matthias-Wandel/jhead/commit/d3cb0a77fa8bee98e2273e45fba63b71ad84b3a9

EPSS

Процентиль: 52%
0.00734
Низкий

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 2 лет назад

A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function PrintFormatNumber of the file exif.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257711.

CVSS3: 6.5
redhat
больше 2 лет назад

A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function PrintFormatNumber of the file exif.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257711.

CVSS3: 6.3
nvd
больше 2 лет назад

A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function PrintFormatNumber of the file exif.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257711.

CVSS3: 6.3
github
больше 2 лет назад

A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function PrintFormatNumber of the file exif.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257711.

EPSS

Процентиль: 52%
0.00734
Низкий