PT-2023-12950 · Matthias Wandel+1 · Jhead+1

Marsman1996

·

Published

2023-06-13

·

Updated

2025-01-03

·

CVE-2022-28550

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Matthias-Wandel/jhead version 3.06
Description The issue arises from jhead copying strings to a stack buffer when it detects a &i or &o, without checking the boundary of the stack buffer. This results in a stack buffer overflow problem when multiple &i or &o are given. The problem is related to the shellescape() function in jhead.c.
Recommendations For version 3.06, consider avoiding the use of multiple &i or &o to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2022-28550

Affected Products

Debian
Jhead