VDB
CVE-2021-28275
CVE-2021-28275
PUBLISHED
CVSS 5.5 MEDIUM
A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.
EPSS 0.66% · 49.2th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
0.66%
49.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| jhead_project | jhead | 3.04, 3.05 |
| n/a | n/a | n/a |
Timeline
- Mar 23, 2022 CVE Published
- Mar 24, 2022 EPSS Score
- May 14, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Aug 25, 2022 EPSS Score
- Oct 15, 2022 EPSS Score
- Dec 6, 2022 EPSS Score
- Jan 26, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 18, 2023 EPSS Score
- May 8, 2023 EPSS Score
- Jun 28, 2023 EPSS Score
References
- GLSA-202210-17 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-28275 advisory
- https://github.com/Matthias-Wandel/jhead/issues/17 exploit