Bugzilla – Bug 1214236
VUL-0: CVE-2020-28840: jhead: buffer overflow in process_COM()
Last modified: 2023-08-14 08:16:40 UTC
CVE-2020-28840 Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS). References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-28840 https://www.cve.org/CVERecord?id=CVE-2020-28840 https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/1900820 https://github.com/F-ZhaoYang/jhead/security/advisories/GHSA-xh27-xwgj-gqw2 https://github.com/Matthias-Wandel/jhead/commit/4827ed31c226dc5ed93603bd649e0e387a1778da https://github.com/Matthias-Wandel/jhead/issues/8
We have 3.06 and newer, so this is already fixed: - openSUSE:Backports:SLE-15-SP4 3.06.0.1 - openSUSE:Backports:SLE-15-SP5 3.06.0.1 - openSUSE:Factory 3.08 Closing.