jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.
References
Link | Resource |
---|---|
https://bugs.gentoo.org/711220#c3 | Issue Tracking Third Party Advisory |
https://bugs.gentoo.org/876247#c0 | Issue Tracking Third Party Advisory |
https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/1858746 | Exploit Issue Tracking Third Party Advisory |
https://security.gentoo.org/glsa/202007-17 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-01-09T00:00:00
Updated: 2022-10-12T00:00:00
Reserved: 2020-01-09T00:00:00
Link: CVE-2020-6625
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-01-09T01:15:16.820
Modified: 2022-11-08T02:50:36.437
Link: CVE-2020-6625
JSON object: View
Redhat Information
No data.
CWE