Vulnerabilities > CVE-2021-28275 - Incorrect Type Conversion or Cast vulnerability in Jhead Project Jhead 3.04/3.05

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
jhead-project
CWE-704

Summary

A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause segmentation fault via a crafted_file.

Vulnerable Configurations

Part Description Count
Application
Jhead_Project
2

Common Weakness Enumeration (CWE)