CVE-2008-4575: Buffer Overflow
Published Oct 15, 2008
·Updated
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."
Affected Software
20 affected components
Sentex Jhead=2.6
Sentex Jhead=1.5
Sentex Jhead=2.3
Sentex Jhead=2.5
Sentex Jhead=1.3
Sentex Jhead=2.4-2
Sentex Jhead=1.2
Sentex Jhead=1.8
Sentex Jhead=2.0
Sentex Jhead=2.7
Sentex Jhead=2.4-1
Sentex Jhead=1.6
Sentex Jhead=2.4
Sentex Jhead=1.9
Sentex Jhead=1.7
Sentex Jhead=1.4
Sentex Jhead=2.1
Sentex Jhead<=2.82
Sentex Jhead=2.8
Sentex Jhead=2.2
Remediation
Patch Available
Event History
Oct 15, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4575?
CVE-2008-4575 has a severity rating that suggests it can lead to denial of service conditions.
2
How do I fix CVE-2008-4575?
To fix CVE-2008-4575, you should upgrade to jhead version 2.84 or later.
3
What versions of jhead are affected by CVE-2008-4575?
CVE-2008-4575 affects jhead versions prior to 2.84 and several earlier versions including 1.2 to 2.8.
4
What kind of exploit does CVE-2008-4575 enable?
CVE-2008-4575 enables attackers to exploit a buffer overflow leading to a potential crash of the application.
5
Is CVE-2008-4575 a remote or local vulnerability?
CVE-2008-4575 is a context-dependent vulnerability, which means it may require local access to exploit effectively.