A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/Matthias-Wandel/jhead/issues/15 | third party advisory issue tracking exploit |
https://security.gentoo.org/glsa/202210-17 | third party advisory vendor advisory |