CVE-2008-4575
published 2008-10-15CVE-2008-4575: Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.73%
75.0th percentile
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jhead | < jhead 2.84-1 (bookworm) | jhead 2.84-1 (bookworm) |
| jhead_project | jhead | >= 0 < 2.84-1 | 2.84-1 |
| jhead_project | jhead | >= 0 < 2.84-1 | 2.84-1 |
| jhead_project | jhead | >= 0 < 2.84-1 | 2.84-1 |
| jhead_project | jhead | >= 0 < 2.84-1 | 2.84-1 |
| sentex | jhead | <= 2.82 | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-49v5-vhqj-7pjx: Buffer overflow in the DoCommand function in jhead before 2
ghsa_unreviewed·2022-05-02
CVE-2008-4575 [MEDIUM] CWE-119 GHSA-49v5-vhqj-7pjx: Buffer overflow in the DoCommand function in jhead before 2
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."
OSV
CVE-2008-4575: Buffer overflow in the DoCommand function in jhead before 2
osv·2008-10-15·CVSS 5.0
CVE-2008-4575 [MEDIUM] CVE-2008-4575: Buffer overflow in the DoCommand function in jhead before 2
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."
Red Hat
jhead buffer overflow
vendor_redhat·2008-10-15·CVSS 5.0
CVE-2008-4575 [MEDIUM] jhead buffer overflow
jhead buffer overflow
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."
Debian
CVE-2008-4575: jhead - Buffer overflow in the DoCommand function in jhead before 2.84 might allow conte...
vendor_debian·2008·CVSS 5.0
CVE-2008-4575 [MEDIUM] CVE-2008-4575: jhead - Buffer overflow in the DoCommand function in jhead before 2.84 might allow conte...
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."
Scope: local
bookworm: resolved (fixed in 2.84-1)
bullseye: resolved (fixed in 2.84-1)
forky: resolved (fixed in 2.84-1)
sid: resolved (fixed in 2.84-1)
trixie: resolved (fixed in 2.84-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-4575 jhead buffer overflow [F9]
bugzilla·2008-10-16·CVSS 5.0
CVE-2008-4575 [MEDIUM] CVE-2008-4575 jhead buffer overflow [F9]
CVE-2008-4575 jhead buffer overflow [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=467264,
---
jhead-2.84-1.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/jhead-2.84-1.fc9
---
jhead-2.84-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2008-4575 jhead buffer overflow [F8]
bugzilla·2008-10-16·CVSS 5.0
CVE-2008-4575 [MEDIUM] CVE-2008-4575 jhead buffer overflow [F8]
CVE-2008-4575 jhead buffer overflow [F8]
F8 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%208&bugs=467263,
---
jhead-2.84-1.fc8 has been submitted as an update for Fedora 8.
http://admin.fedoraproject.org/updates/jhead-2.84-1.fc8
---
jhead-2.84-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2008-4575 jhead buffer overflow
bugzilla·2008-10-16·CVSS 5.0
CVE-2008-4575 [MEDIUM] CVE-2008-4575 jhead buffer overflow
CVE-2008-4575 jhead buffer overflow
Buffer overflow in the DoCommand function in jhead before 2.84 might
allow context-dependent attackers to cause a denial of service (crash)
via (1) a long -cmd argument and (2) possibly other unspecified
vectors.
Reference: http://www.openwall.com/lists/oss-security/2008/10/15/6
Reference: http://www.sentex.net/~mwandel/jhead/changes.txt
Reference: https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/271020
Discussion:
jhead-2.84-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
jhead-2.84-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue was addressed in:
Fedora:
https://adm
http://secunia.com/advisories/32363http://www.openwall.com/lists/oss-security/2008/10/15/6http://www.securityfocus.com/bid/31770http://www.sentex.net/~mwandel/jhead/changes.txthttps://bugs.launchpad.net/ubuntu/+source/jhead/+bug/271020https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00511.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-October/msg00531.htmlhttp://secunia.com/advisories/32363http://www.openwall.com/lists/oss-security/2008/10/15/6http://www.securityfocus.com/bid/31770http://www.sentex.net/~mwandel/jhead/changes.txthttps://bugs.launchpad.net/ubuntu/+source/jhead/+bug/271020https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00511.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-October/msg00531.html
2008-10-15
Published