CVE-2018-17088: Integer Overflow
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a location exceeds the EXIF data length. This is analogous to the CVE-2016-3822 integer overflow in exif.c. This gpsinfo.c vulnerability is unrelated to the CVE-2018-16554 gpsinfo.c vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-17088?
The severity of CVE-2018-17088 is high.
How does CVE-2018-17088 impact jhead 3.00?
CVE-2018-17088 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file.
How can I fix CVE-2018-17088?
There is currently no known fix for CVE-2018-17088. It is recommended to update to the latest version of jhead if available or consider using an alternative software.
What is the Common Vulnerabilities and Exposures (CVE) ID of this vulnerability?
The Common Vulnerabilities and Exposures (CVE) ID of this vulnerability is CVE-2018-17088.
What is the Common Weakness Enumeration (CWE) ID of this vulnerability?
The Common Weakness Enumeration (CWE) ID of this vulnerability is CWE-190.