CVE-2018-6612 PUBLISHED

An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicious JPEG file, which may allow a remote attacker to cause a denial-of-service attack or unspecified other impact.

EPSS 0.16% · 37.0th percentile

Risk Scores

EPSS Score
0.16%
37.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSjhead0, 1:2.97-1, 1:2.97-1+deb8u1build0.14.04.1
Ubuntu:Pro:16.04:LTSjhead*, 0, 1:3.00-4+deb9u1build0.16.04.1

Timeline

References

Open in Interactive Console →