CVE-2022-41751
published 2022-10-17CVE-2022-41751: Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.44%
35.9th percentile
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | jhead | < jhead 1:3.06.0.1-3 (bookworm) | jhead 1:3.06.0.1-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jhead_project | jhead | — | — |
| jhead_project | jhead | >= 0 < 1:3.04-6+deb11u1 | 1:3.04-6+deb11u1 |
| jhead_project | jhead | >= 0 < 1:3.06.0.1-3 | 1:3.06.0.1-3 |
| jhead_project | jhead | >= 0 < 1:3.06.0.1-3 | 1:3.06.0.1-3 |
| jhead_project | jhead | >= 0 < 1:3.06.0.1-3 | 1:3.06.0.1-3 |
| jhead_project | jhead | >= 0 < 1:3.00-8~ubuntu0.2 | 1:3.00-8~ubuntu0.2 |
| jhead_project | jhead | >= 0 < 1:3.04-1ubuntu0.2 | 1:3.04-1ubuntu0.2 |
| jhead_project | jhead | >= 0 < 1:3.06.0.1-2ubuntu0.22.04.1 | 1:3.06.0.1-2ubuntu0.22.04.1 |
| jhead_project | jhead | >= 0 < 1:2.97-1+deb8u2ubuntu0.1~esm2 | 1:2.97-1+deb8u2ubuntu0.1~esm2 |
| jhead_project | jhead | >= 0 < 1:3.00-4+deb9u1ubuntu0.1~esm2 | 1:3.00-4+deb9u1ubuntu0.1~esm2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Jhead vulnerabilities
osv·2023-05-25·CVSS 7.8
CVE-2021-34055 [HIGH] Jhead vulnerabilities
Jhead vulnerabilities
It was discovered that Jhead did not properly handle certain crafted images
while rotating them. An attacker could possibly use this issue to crash Jhead,
resulting in a denial of service. (CVE-2021-34055)
Kyle Brown discovered that Jhead did not properly handle certain crafted
images while regenerating the Exif thumbnail. An attacker could possibly use
this issue to execute arbitrary commands. (CVE-2022-41751)
GHSA
GHSA-8m3f-vphm-cjhj: Jhead 3
ghsa_unreviewed·2022-10-17
CVE-2022-41751 [HIGH] CWE-78 GHSA-8m3f-vphm-cjhj: Jhead 3
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
OSV
CVE-2022-41751: Jhead 3
osv·2022-10-17·CVSS 7.8
CVE-2022-41751 [HIGH] CVE-2022-41751: Jhead 3
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
Ubuntu
Jhead vulnerabilities
vendor_ubuntu·2023-05-25·CVSS 7.8
CVE-2022-41751 [HIGH] Jhead vulnerabilities
Title: Jhead vulnerabilities
Summary: Jhead could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that Jhead did not properly handle certain crafted images
while rotating them. An attacker could possibly use this issue to crash Jhead,
resulting in a denial of service. (CVE-2021-34055)
Kyle Brown discovered that Jhead did not properly handle certain crafted
images while regenerating the Exif thumbnail. An attacker could possibly use
this issue to execute arbitrary commands. (CVE-2022-41751)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-41751: jhead - Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them...
vendor_debian·2022·CVSS 7.8
CVE-2022-41751 [HIGH] CVE-2022-41751: jhead - Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them...
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
Scope: local
bookworm: resolved (fixed in 1:3.06.0.1-3)
bullseye: resolved (fixed in 1:3.04-6+deb11u1)
forky: resolved (fixed in 1:3.06.0.1-3)
sid: resolved (fixed in 1:3.06.0.1-3)
trixie: resolved (fixed in 1:3.06.0.1-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/Matthias-Wandel/jheadhttps://github.com/Matthias-Wandel/jhead/blob/63ce118c6a59ea64ac357236a11a47aaf569d622/jhead.c#L788https://github.com/Matthias-Wandel/jhead/pull/57https://lists.debian.org/debian-lts-announce/2022/12/msg00004.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NM6FET4ZNWV4EQGKZTLZFWTNVODGVOK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EG26AD7KJAY5B6L6OERSGL4FRXJE3GOB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAVB3ZX7E5ULEXESU5NXZIAHY6CVGCHB/https://www.debian.org/security/2022/dsa-5294https://github.com/Matthias-Wandel/jheadhttps://github.com/Matthias-Wandel/jhead/blob/63ce118c6a59ea64ac357236a11a47aaf569d622/jhead.c#L788https://github.com/Matthias-Wandel/jhead/pull/57https://lists.debian.org/debian-lts-announce/2022/12/msg00004.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NM6FET4ZNWV4EQGKZTLZFWTNVODGVOK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EG26AD7KJAY5B6L6OERSGL4FRXJE3GOB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAVB3ZX7E5ULEXESU5NXZIAHY6CVGCHB/https://www.debian.org/security/2022/dsa-5294
2022-10-17
Published