CVE-2008-4640: Input Validation
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4640?
CVE-2008-4640 is classified as a moderate severity vulnerability due to its potential for local users to delete arbitrary files.
How do I fix CVE-2008-4640?
To fix CVE-2008-4640, update jhead to version 2.85 or later, which addresses this vulnerability.
Who is affected by CVE-2008-4640?
CVE-2008-4640 affects jhead versions 2.84 and earlier, as well as all versions up to 1.9 inclusive.
What are the implications of CVE-2008-4640?
The implications of CVE-2008-4640 include the ability for an attacker with local access to delete files, potentially leading to data loss.
Is there a known exploit for CVE-2008-4640?
Yes, exploitation of CVE-2008-4640 requires local access and involves manipulating the input filename to delete files.