CVE-2020-6625: High severity Jhead Project Jhead vulnerability
Published Jan 9, 2020
·Updated
jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.
Affected Software
1 affected component
Jhead Project Jhead<=3.04
Event History
Jan 9, 2020
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-6625?
The severity of CVE-2020-6625 is high with a CVSS score of 7.1.
2
What software is affected by CVE-2020-6625?
The affected software is Jhead Project Jhead version 3.04.
3
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-6625?
The CWE ID for CVE-2020-6625 is CWE-125 (Out-of-bounds Read).
4
What is the vulnerability description of CVE-2020-6625?
CVE-2020-6625 is a heap-based buffer over-read vulnerability in Jhead through 3.04 when called from ProcessGpsInfo in gpsinfo.c.
5
How can I fix the CVE-2020-6625 vulnerability?
To fix the CVE-2020-6625 vulnerability, it is recommended to update Jhead to the latest version available.