CVE-2021-3496: Buffer Overflow
Published Apr 13, 2021
·Updated
A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.
Affected Software
2 affected componentsFixes available
redhat/jhead<3.06.0.1
3.06.0.1
Jhead Project Jhead=3.06
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jheadto a version that resolves this vulnerability.Fixed in 3.06.0.1
Event History
Apr 22, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this heap-based buffer overflow?
The vulnerability ID is CVE-2021-3496.
2
What is the severity of CVE-2021-3496?
The severity of CVE-2021-3496 is high.
3
Which software versions are affected by CVE-2021-3496?
The software version 3.06 of Jhead is affected by CVE-2021-3496.
4
How can I fix the heap-based buffer overflow vulnerability in Jhead?
Update Jhead to a version that has the vulnerability patched, such as version 3.07 or later.
5
Can you provide more information about CVE-2021-3496?
You can find more information about CVE-2021-3496 in the references provided: [1](https://bugzilla.redhat.com/show_bug.cgi?id=1949245), [2](https://github.com/Matthias-Wandel/jhead/issues/33), [3](https://security.gentoo.org/glsa/202210-17).