CVE-2016-3822
published 2016-08-05CVE-2016-3822: exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01…
PriorityP337high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.27%
66.5th percentile
exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds access) via crafted EXIF data, aka internal bug 28868315.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | jhead | < jhead 1:3.00-8 (bookworm) | jhead 1:3.00-8 (bookworm) |
| debian | jhead | < jhead 1:3.00-4 (bookworm) | jhead 1:3.00-4 (bookworm) |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2018-17088: jhead - The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remo...
vendor_debian·2018·CVSS 7.8
CVE-2018-17088 [HIGH] CVE-2018-17088: jhead - The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remo...
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a location exceeds the EXIF data length. This is analogous to the CVE-2016-3822 integer overflow in exif.c. This gpsinfo.c vulnerability is unrelated to the CVE-2018-16554 gpsinfo.c vulnerability.
Scope: local
bookworm: resolved (fixed in 1:3.00-8)
bullseye: resolved (fixed in 1:3.00-8)
forky: resolved (fixed in 1:3.00-8)
sid: resolved (fixed in 1:3.00-8)
trixie: resolved (fixed in 1:3.00-8)
Android
CVE-2016-3822: Android Security Bulletin 2016-08-01
CVE: CVE-2016-3822
Severity: HIGH
Affected AOSP versions: 4
vendor_android·2016-08-01·CVSS 7.8
CVE-2016-3822 [HIGH] CVE-2016-3822: Android Security Bulletin 2016-08-01
CVE: CVE-2016-3822
Severity: HIGH
Affected AOSP versions: 4
Android Security Bulletin 2016-08-01
CVE: CVE-2016-3822
Severity: HIGH
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1
References: A-28868315
Debian
CVE-2016-3822: jhead - exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before ...
vendor_debian·2016·CVSS 7.8
CVE-2016-3822 [HIGH] CVE-2016-3822: jhead - exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before ...
exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds access) via crafted EXIF data, aka internal bug 28868315.
Scope: local
bookworm: resolved (fixed in 1:3.00-4)
bullseye: resolved (fixed in 1:3.00-4)
forky: resolved (fixed in 1:3.00-4)
sid: resolved (fixed in 1:3.00-4)
trixie: resolved (fixed in 1:3.00-4)
GHSA
GHSA-vq3j-5p4r-99x3: exif
ghsa_unreviewed·2022-05-14
CVE-2016-3822 [HIGH] CWE-119 GHSA-vq3j-5p4r-99x3: exif
exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds access) via crafted EXIF data, aka internal bug 28868315.
GHSA
GHSA-727r-rxp4-hwwc: The ProcessGpsInfo function of the gpsinfo
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2018-17088 [HIGH] CWE-190 GHSA-727r-rxp4-hwwc: The ProcessGpsInfo function of the gpsinfo
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a location exceeds the EXIF data length. This is analogous to the CVE-2016-3822 integer overflow in exif.c. This gpsinfo.c vulnerability is unrelated to the CVE-2018-16554 gpsinfo.c vulnerability.
OSV
CVE-2018-17088: The ProcessGpsInfo function of the gpsinfo
osv·2018-09-16·CVSS 7.8
CVE-2018-17088 [HIGH] CVE-2018-17088: The ProcessGpsInfo function of the gpsinfo
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a location exceeds the EXIF data length. This is analogous to the CVE-2016-3822 integer overflow in exif.c. This gpsinfo.c vulnerability is unrelated to the CVE-2018-16554 gpsinfo.c vulnerability.
OSV
CVE-2016-3822: exif
osv·2016-08-05·CVSS 7.8
CVE-2016-3822 [HIGH] CVE-2016-3822: exif
exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds access) via crafted EXIF data, aka internal bug 28868315.
No detection rules found.
No public exploits indexed.
http://source.android.com/security/bulletin/2016-08-01.htmlhttp://www.debian.org/security/2017/dsa-3825http://www.securityfocus.com/bid/92226https://android.googlesource.com/platform/external/jhead/+/bae671597d47b9e5955c4cb742e468cebfd7ca6bhttp://source.android.com/security/bulletin/2016-08-01.htmlhttp://www.debian.org/security/2017/dsa-3825http://www.securityfocus.com/bid/92226https://android.googlesource.com/platform/external/jhead/+/bae671597d47b9e5955c4cb742e468cebfd7ca6b
2016-08-05
Published