CVE-2021-28278: Buffer Overflow
Published Mar 23, 2022
·Updated
A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.
Affected Software
2 affected components
Jhead Project Jhead=3.04
Jhead Project Jhead=3.05
Event History
Mar 23, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2021-28278?
CVE-2021-28278 is a Heap-based Buffer Overflow vulnerability in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.
2
How severe is CVE-2021-28278?
CVE-2021-28278 has a severity score of 7.8 (high).
3
What is the affected software?
The affected software is Jhead Project Jhead version 3.04 and 3.05.
4
How can I fix CVE-2021-28278?
There is no known fix currently available. It is recommended to update to the latest version of Jhead when a fix becomes available.
5
Where can I find more information about CVE-2021-28278?
More information about CVE-2021-28278 can be found at the following references: [GitHub](https://github.com/Matthias-Wandel/jhead/issues/15) and [Gentoo Security](https://security.gentoo.org/glsa/202210-17).