605
VMScore

CVE-2021-3496

Published: 22/04/2021 Updated: 07/12/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jhead project jhead 3.06

Vendor Advisories

Debian Bug report logs - #972617 heap-buffer-overflow on jhead-304/jpgfilec:285 ReadJpegSections Package: jhead; Maintainer for jhead is Joachim Reichel <reichel@debianorg>; Source for jhead is src:jhead (PTS, buildd, popcon) Reported by: Fstark <f734222792@gmailcom> Date: Wed, 21 Oct 2020 10:15:02 UTC Severity: ...
Debian Bug report logs - #986923 jhead: CVE-2021-3496 Package: src:jhead; Maintainer for src:jhead is Debian QA Group <packages@qadebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 14 Apr 2021 12:12:01 UTC Severity: grave Tags: security, upstream Found in version jhead/1:304-5 Forward ...
A heap-based buffer overflow was found in jhead in version 306 in Get16u() in exifc when processing a crafted file ...