First published: Wed Mar 23 2022(Updated: )
A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jhead Project Jhead | =3.04 | |
Jhead Project Jhead | =3.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28278 is a Heap-based Buffer Overflow vulnerability in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.
CVE-2021-28278 has a severity score of 7.8 (high).
The affected software is Jhead Project Jhead version 3.04 and 3.05.
There is no known fix currently available. It is recommended to update to the latest version of Jhead when a fix becomes available.
More information about CVE-2021-28278 can be found at the following references: [GitHub](https://github.com/Matthias-Wandel/jhead/issues/15) and [Gentoo Security](https://security.gentoo.org/glsa/202210-17).