Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Hanfang Zhang

Pesquisador deSichuan University
#17145de 53,633
15.6CVSS total
Vulnerabilidades · 2
Alta
2
PT-2018-13629
7.8
2018-09-16
Jhead · Jhead · CVE-2018-16554
**Name of the Vulnerable Software and Affected Versions** jhead version 3.00 **Description** The issue is related to the ProcessGpsInfo function in the gpsinfo.c file, which may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file. This is due to an inconsistency between float and double in a sprintf format string during TAG GPS ALT handling. **Recommendations** For jhead version 3.00, as a temporary workaround, consider disabling the ProcessGpsInfo function until a patch is available. Restrict access to handling of TAG GPS ALT to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2018-13887
7.8
2018-09-16
Alt · Alt Linux · CVE-2018-17088
Name of the Vulnerable Software and Affected Versions: ALT Linux (affected versions not specified) Description: The issue concerns a package vulnerability in ALT Linux. No further details are provided about the nature of the vulnerability, affected devices, or real-world incidents. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.