ALT-PU-2022-3480-1
Package jhead updated to version 3.06.0.1-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-6624
jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
- https://bugs.gentoo.org/711220#c3
- https://bugs.gentoo.org/876247#c0
- https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/1858744
- https://security.gentoo.org/glsa/202007-17
- https://bugs.gentoo.org/711220#c3
- https://bugs.gentoo.org/876247#c0
- https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/1858744
- https://security.gentoo.org/glsa/202007-17
Modified: 2024-11-21
CVE-2020-6625
jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.
- https://bugs.gentoo.org/711220#c3
- https://bugs.gentoo.org/876247#c0
- https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/1858746
- https://security.gentoo.org/glsa/202007-17
- https://bugs.gentoo.org/711220#c3
- https://bugs.gentoo.org/876247#c0
- https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/1858746
- https://security.gentoo.org/glsa/202007-17
Modified: 2024-11-21
CVE-2021-28275
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.
Modified: 2024-11-21
CVE-2021-28276
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c.
Modified: 2024-11-21
CVE-2021-28277
A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c.
Modified: 2024-11-21
CVE-2021-28278
A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.