CVE-2021-28275: Incorrect Type Cast
Published Mar 23, 2022
·Updated
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a craftedfile.
Affected Software
2 affected components
Jhead Project Jhead=3.04
Jhead Project Jhead=3.05
Event History
Mar 23, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2021-28275?
CVE-2021-28275 is a Denial of Service vulnerability in jhead 3.04 and 3.05 that can cause a segmentation fault via a crafted file.
2
How severe is CVE-2021-28275?
CVE-2021-28275 has a severity value of 5.5, which is considered medium.
3
Which software versions are affected by CVE-2021-28275?
CVE-2021-28275 affects jhead versions 3.04 and 3.05.
4
How can I fix the CVE-2021-28275 vulnerability?
To fix the CVE-2021-28275 vulnerability, update jhead to a version that is not affected, such as 3.06 or later.
5
Where can I find more information about CVE-2021-28275?
You can find more information about CVE-2021-28275 on the GitHub issue page (https://github.com/Matthias-Wandel/jhead/issues/17) and the Gentoo security advisory (https://security.gentoo.org/glsa/202210-17).