jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
References
Link | Resource |
---|---|
https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/1858744 | Exploit Issue Tracking Third Party Advisory |
https://security.gentoo.org/glsa/202007-17 | Third Party Advisory |
https://bugs.gentoo.org/711220#c3 | Issue Tracking Third Party Advisory |
https://bugs.gentoo.org/876247#c0 | Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2020-01-08 17:15
Updated : 2022-11-07 19:25
NVD link : CVE-2020-6624
Mitre link : CVE-2020-6624
JSON object : View
CWE
CWE-125
Out-of-bounds Read
Products Affected
jhead_project
- jhead