CVE-2008-4641 — Improper Input Validation in Jhead
Severity
10.0CRITICALNVD
EPSS
2.0%
top 16.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 21
Latest updateMay 17
Description
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input.
CVSS vector
AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0
Affected Packages3 packages
🔴Vulnerability Details
2📋Vendor Advisories
2💬Community
1Bugzilla
▶