PT-2022-9884 · Jhead+4 · Jhead+4
Published
2021-04-26
·
Updated
2023-05-23
·
CVE-2021-28276
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
jhead versions 3.04 through 3.05
Description
A Denial of Service issue exists via a wild address read in the
ProcessCanonMakerNoteDir function in makernote.c.Recommendations
For jhead versions 3.04 and 3.05, consider disabling the
ProcessCanonMakerNoteDir function until a patch is available.
Restrict access to the makernote.c module to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Ubuntu
Jhead