MGASA-2017-0105

Source
https://advisories.mageia.org/MGASA-2017-0105.html
Import Source
https://advisories.mageia.org/MGASA-2017-0105.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2017-0105
Related
Published
2017-04-04T06:44:05Z
Modified
2017-04-04T06:32:34Z
Summary
Updated jhead packages fix security vulnerability
Details

It was discovered that jhead, a tool to manipulate the non-image part of EXIF compliant JPEG files, is prone to an out-of-bounds access vulnerability, which may result in denial of service or, potentially, the execution of arbitrary code if an image with specially crafted EXIF data is processed.

References
Credits

Affected packages

Mageia:5 / jhead

Package

Name
jhead
Purl
pkg:rpm/mageia/jhead?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.97-4.1.mga5

Ecosystem specific

{
    "section": "core"
}