Vulnerability Description
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Matthiaswandel | Jhead | < 3.04 |
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/1900820ExploitIssue Tracking
- https://github.com/F-ZhaoYang/jhead/security/advisories/GHSA-xh27-xwgj-gqw2Exploit
- https://github.com/Matthias-Wandel/jhead/commit/4827ed31c226dc5ed93603bd649e0e38Patch
- https://github.com/Matthias-Wandel/jhead/issues/8ExploitIssue TrackingPatch
- https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/1900820ExploitIssue Tracking
- https://github.com/F-ZhaoYang/jhead/security/advisories/GHSA-xh27-xwgj-gqw2Exploit
- https://github.com/Matthias-Wandel/jhead/commit/4827ed31c226dc5ed93603bd649e0e38Patch
- https://github.com/Matthias-Wandel/jhead/issues/8ExploitIssue TrackingPatch
FAQ
What is CVE-2020-28840?
CVE-2020-28840 is a vulnerability with a CVSS score of 7.8 (HIGH). Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
How severe is CVE-2020-28840?
CVE-2020-28840 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28840?
Check the references section above for vendor advisories and patch information. Affected products include: Matthiaswandel Jhead.