CVE-2008-4640
published 2008-10-21CVE-2008-4640: The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input…
PriorityP411low3.6CVSS 2.0
AVLACLAuNCNIPAP
EPSS
0.30%
22.2th percentile
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jhead | < jhead 2.85-1 (bookworm) | jhead 2.85-1 (bookworm) |
| jhead_project | jhead | >= 0 < 2.85-1 | 2.85-1 |
| jhead_project | jhead | >= 0 < 2.85-1 | 2.85-1 |
| jhead_project | jhead | >= 0 < 2.85-1 | 2.85-1 |
| jhead_project | jhead | >= 0 < 2.85-1 | 2.85-1 |
| sentex | jhead | <= 2.82 | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
| sentex | jhead | — | — |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW
vendor_debian3.6LOW
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jhead: arbitrary file deletion
vendor_redhat·2008-10-15·CVSS 3.6
CVE-2008-4640 [LOW] jhead: arbitrary file deletion
jhead: arbitrary file deletion
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.
Debian
CVE-2008-4640: jhead - The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allo...
vendor_debian·2008·CVSS 3.6
CVE-2008-4640 [LOW] CVE-2008-4640: jhead - The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allo...
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.
Scope: local
bookworm: resolved (fixed in 2.85-1)
bullseye: resolved (fixed in 2.85-1)
forky: resolved (fixed in 2.85-1)
sid: resolved (fixed in 2.85-1)
trixie: resolved (fixed in 2.85-1)
GHSA
GHSA-ph3v-wxq4-4xc6: The DoCommand function in jhead
ghsa_unreviewed·2022-05-17
CVE-2008-4640 [LOW] CWE-20 GHSA-ph3v-wxq4-4xc6: The DoCommand function in jhead
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.
OSV
CVE-2008-4640: The DoCommand function in jhead
osv·2008-10-21·CVSS 3.6
CVE-2008-4640 [LOW] CVE-2008-4640: The DoCommand function in jhead
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2008/10/16/3http://www.openwall.com/lists/oss-security/2008/11/26/4http://www.securityfocus.com/bid/32506https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/271020http://www.openwall.com/lists/oss-security/2008/10/16/3http://www.openwall.com/lists/oss-security/2008/11/26/4http://www.securityfocus.com/bid/32506https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/271020
2008-10-21
Published