PT-2019-11555 · Matthew Mccormick+4 · Jhead+4

Jianzhong Liu

·

Published

2019-07-15

·

Updated

2023-08-24

·

CVE-2019-1010302

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: jhead version 3.03
Description: The issue is related to incorrect access control, which can lead to a denial of service. This occurs when the victim opens a specially crafted JPEG file, affecting the iptc.c component, specifically the show IPTC() function at line 122.
Recommendations: For jhead version 3.03, as a temporary workaround, consider avoiding the use of the show IPTC() function in the iptc.c component until a patch is available. Restrict access to specially crafted JPEG files to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2540
ALT-PU-2019-3269
ALT-PU-2023-5099
CVE-2019-1010302
DLA-2054-1
MGASA-2020-0014
OPENSUSE-SU-2021:0743-1
OPENSUSE-SU-2021:0752-1
OPENSUSE-SU-2021_0743-1
USN-6098-1

Affected Products

Alt Linux
Linuxmint
Suse
Ubuntu
Jhead