Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jhead | Dec 6, 2022 | Oct 17, 2022 |
| Gentoo Linux | — | Upgrade media-gfx/jhead. | Jun 24, 2024 | Oct 17, 2022 |
| Suse | — | Upgrade jhead | Nov 1, 2022 | Oct 17, 2022 |
| Ubuntu | — | Upgrade jhead (Ubuntu Pro)Upgrade jhead | May 29, 2023 | Oct 17, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub