CVE-2018-16554 PUBLISHED

The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT handling.

EPSS 0.30% · 52.7th percentile

Risk Scores

EPSS Score
0.30%
52.7th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSjhead0, 1:3.00-4, 1:3.00-5
Ubuntu:Pro:14.04:LTSjhead1:2.97-1, 1:2.97-1+deb8u1build0.14.04.1, 0

Timeline

References

Open in Interactive Console →