CVE-2018-16554: High severity jhead vulnerability
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAGGPSALT handling.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-16554?
CVE-2018-16554 is a vulnerability in the ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00, allowing a remote attacker to cause a denial-of-service attack or other unspecified impact via a malicious JPEG file.
How does CVE-2018-16554 affect jhead?
CVE-2018-16554 affects jhead version 3.00.
How severe is CVE-2018-16554?
CVE-2018-16554 has a severity rating of 7.8 (high).
How can I fix CVE-2018-16554?
To fix CVE-2018-16554, upgrade to jhead version 3.04 or higher.
Where can I find more information about CVE-2018-16554?
You can find more information about CVE-2018-16554 at the following references: [link1](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=908176), [link2](https://lists.debian.org/debian-lts-announce/2019/12/msg00037.html), [link3](https://nimo-zhang.github.io/2018/09/07/bug-analysis-1/#more)