CVE-2021-34055
published 2022-11-04CVE-2021-34055: jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
PriorityP434high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.42%
34.3th percentile
jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | jhead | < jhead 1:3.06.0.1-5 (bookworm) | jhead 1:3.06.0.1-5 (bookworm) |
| jhead_project | jhead | — | — |
| jhead_project | jhead | >= 0 < 1:3.04-6+deb11u1 | 1:3.04-6+deb11u1 |
| jhead_project | jhead | >= 0 < 1:3.06.0.1-5 | 1:3.06.0.1-5 |
| jhead_project | jhead | >= 0 < 1:3.06.0.1-5 | 1:3.06.0.1-5 |
| jhead_project | jhead | >= 0 < 1:3.06.0.1-5 | 1:3.06.0.1-5 |
| jhead_project | jhead | >= 0 < 1:3.00-8~ubuntu0.2 | 1:3.00-8~ubuntu0.2 |
| jhead_project | jhead | >= 0 < 1:3.04-1ubuntu0.2 | 1:3.04-1ubuntu0.2 |
| jhead_project | jhead | >= 0 < 1:3.06.0.1-2ubuntu0.22.04.1 | 1:3.06.0.1-2ubuntu0.22.04.1 |
| jhead_project | jhead | >= 0 < 1:2.97-1+deb8u2ubuntu0.1~esm2 | 1:2.97-1+deb8u2ubuntu0.1~esm2 |
| jhead_project | jhead | >= 0 < 1:3.00-4+deb9u1ubuntu0.1~esm2 | 1:3.00-4+deb9u1ubuntu0.1~esm2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Jhead vulnerabilities
osv·2023-05-25·CVSS 7.8
CVE-2021-34055 [HIGH] Jhead vulnerabilities
Jhead vulnerabilities
It was discovered that Jhead did not properly handle certain crafted images
while rotating them. An attacker could possibly use this issue to crash Jhead,
resulting in a denial of service. (CVE-2021-34055)
Kyle Brown discovered that Jhead did not properly handle certain crafted
images while regenerating the Exif thumbnail. An attacker could possibly use
this issue to execute arbitrary commands. (CVE-2022-41751)
GHSA
GHSA-fxjw-w469-wq6w: jhead 3
ghsa_unreviewed·2022-11-04
CVE-2021-34055 [HIGH] CWE-120 GHSA-fxjw-w469-wq6w: jhead 3
jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
OSV
CVE-2021-34055: jhead 3
osv·2022-11-04·CVSS 7.8
CVE-2021-34055 [HIGH] CVE-2021-34055: jhead 3
jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
Ubuntu
Jhead vulnerabilities
vendor_ubuntu·2023-05-25·CVSS 7.8
CVE-2022-41751 [HIGH] Jhead vulnerabilities
Title: Jhead vulnerabilities
Summary: Jhead could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that Jhead did not properly handle certain crafted images
while rotating them. An attacker could possibly use this issue to crash Jhead,
resulting in a denial of service. (CVE-2021-34055)
Kyle Brown discovered that Jhead did not properly handle certain crafted
images while regenerating the Exif thumbnail. An attacker could possibly use
this issue to execute arbitrary commands. (CVE-2022-41751)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-34055: jhead - jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
vendor_debian·2021·CVSS 7.8
CVE-2021-34055 [HIGH] CVE-2021-34055: jhead - jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
Scope: local
bookworm: resolved (fixed in 1:3.06.0.1-5)
bullseye: resolved (fixed in 1:3.04-6+deb11u1)
forky: resolved (fixed in 1:3.06.0.1-5)
sid: resolved (fixed in 1:3.06.0.1-5)
trixie: resolved (fixed in 1:3.06.0.1-5)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/Matthias-Wandel/jhead/issues/36https://lists.debian.org/debian-lts-announce/2022/12/msg00004.htmlhttps://www.debian.org/security/2022/dsa-5294https://github.com/Matthias-Wandel/jhead/issues/36https://lists.debian.org/debian-lts-announce/2022/12/msg00004.htmlhttps://www.debian.org/security/2022/dsa-5294
2022-11-04
Published