CVE-2021-3496Improper Restriction of Operations within the Bounds of a Memory Buffer in Jhead

Severity
7.8HIGHNVD
OSV5.5
EPSS
0.2%
top 60.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateMay 29

Description

A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

debiandebian/jhead< jhead 1:3.04-6 (bookworm)
Debianjhead_project/jhead< 1:3.04-6+3
Ubuntujhead_project/jhead< 1:2.97-1+deb8u2ubuntu0.1~esm3+4
CVEListV5jhead_project/jheadjhead 3.06.0.1

Patches

🔴Vulnerability Details

3
OSV
Jhead vulnerabilities2023-05-29
GHSA
GHSA-rvxv-5pj2-85pq: A heap-based buffer overflow was found in jhead in version 32022-05-24
OSV
CVE-2021-3496: A heap-based buffer overflow was found in jhead in version 32021-04-22

📋Vendor Advisories

2
Ubuntu
Jhead vulnerabilities2023-05-29
Debian
CVE-2021-3496: jhead - A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in e...2021
CVE-2021-3496 — Debian Jhead vulnerability | cvebase