Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer...
Critical severity
Unreviewed
Published
Jun 13, 2023
to the GitHub Advisory Database
•
Updated Jan 3, 2025
Description
Published by the National Vulnerability Database
Jun 13, 2023
Published to the GitHub Advisory Database
Jun 13, 2023
Last updated
Jan 3, 2025
Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the stack buffer. As a result, there will be a stack buffer overflow problem when multiple
&i
or&o
are given.References