Vulnerabilities > CVE-2022-28550 - Out-of-bounds Write vulnerability in Jhead Project Jhead 3.06

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
jhead-project
CWE-787
critical

Summary

Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the stack buffer. As a result, there will be a stack buffer overflow problem when multiple `&i` or `&o` are given.

Vulnerable Configurations

Part Description Count
Application
Jhead_Project
1

Common Weakness Enumeration (CWE)