CVE-2020-28840
published 2023-08-11CVE-2020-28840: Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.0th percentile
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jhead | < jhead 1:3.06.0.1-2 (bookworm) | jhead 1:3.06.0.1-2 (bookworm) |
| jhead_project | jhead | >= 0 < 1:3.06.0.1-2 | 1:3.06.0.1-2 |
| jhead_project | jhead | >= 0 < 1:3.06.0.1-2 | 1:3.06.0.1-2 |
| jhead_project | jhead | >= 0 < 1:3.06.0.1-2 | 1:3.06.0.1-2 |
| matthiaswandel | jhead | < 3.04 | 3.04 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h46m-86hc-7cwf: Buffer Overflow vulnerability in jpgfile
ghsa_unreviewed·2023-08-11
CVE-2020-28840 [HIGH] CWE-120 GHSA-h46m-86hc-7cwf: Buffer Overflow vulnerability in jpgfile
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
OSV
CVE-2020-28840: Buffer Overflow vulnerability in jpgfile
osv·2023-08-11·CVSS 7.8
CVE-2020-28840 [HIGH] CVE-2020-28840: Buffer Overflow vulnerability in jpgfile
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
Debian
CVE-2020-28840: jhead - Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04...
vendor_debian·2020·CVSS 7.8
CVE-2020-28840 [HIGH] CVE-2020-28840: jhead - Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04...
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
Scope: local
bookworm: resolved (fixed in 1:3.06.0.1-2)
bullseye: open
forky: resolved (fixed in 1:3.06.0.1-2)
sid: resolved (fixed in 1:3.06.0.1-2)
trixie: resolved (fixed in 1:3.06.0.1-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/1900820https://github.com/F-ZhaoYang/jhead/security/advisories/GHSA-xh27-xwgj-gqw2https://github.com/Matthias-Wandel/jhead/commit/4827ed31c226dc5ed93603bd649e0e387a1778dahttps://github.com/Matthias-Wandel/jhead/issues/8https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/1900820https://github.com/F-ZhaoYang/jhead/security/advisories/GHSA-xh27-xwgj-gqw2https://github.com/Matthias-Wandel/jhead/commit/4827ed31c226dc5ed93603bd649e0e387a1778dahttps://github.com/Matthias-Wandel/jhead/issues/8
2023-08-11
Published