RSS   Vulnerabilities for 'Jhead'   RSS

2008-10-21
 
CVE-2008-4641

CWE-20
 

 
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input.

 
 
CVE-2008-4640

CWE-noinfo
 

 
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.

 
 
CVE-2008-4639

CWE-noinfo
 

 
jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

 
2008-10-15
 
CVE-2008-4575

CWE-119
 

 
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."

 


Copyright 2024, cxsecurity.com

 

Back to Top