jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
{ "urgency": "unimportant" }