CVE-2021-28277: Buffer Overflow
Published Mar 23, 2022
·Updated
A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c.
Affected Software
2 affected components
Jhead Project Jhead=3.04
Jhead Project Jhead=3.05
Event History
Mar 23, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2021-28277?
CVE-2021-28277 is a Heap-based Buffer Overflow vulnerability in jhead 3.04 and 3.05.
2
How does CVE-2021-28277 affect jhead?
CVE-2021-28277 affects jhead versions 3.04 and 3.05.
3
What is the severity of CVE-2021-28277?
CVE-2021-28277 has a severity rating of 7.8 (high).
4
How can I fix CVE-2021-28277?
To fix CVE-2021-28277, update jhead to a version that is not affected (3.06 or later).
5
Are there any references for CVE-2021-28277?
Yes, you can find references for CVE-2021-28277 at the following links: [link1](https://github.com/Matthias-Wandel/jhead/issues/16) and [link2](https://security.gentoo.org/glsa/202210-17).