Users login

Create an account »

JOIN XATRIX

Users login

Home » Security Advisories» Debian » jhead security update

jhead security update

  • Vendor: Debian
  • Vendor ID: DSA 3825-1
  • Date: March 31, 2017


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3825-1 [email protected]
https://www.debian.org/security/ Salvatore Bonaccorso
March 31, 2017 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : jhead
CVE ID : CVE-2016-3822
Debian Bug : 858213

It was discovered that jhead, a tool to manipulate the non-image part of
EXIF compliant JPEG files, is prone to an out-of-bounds access
vulnerability, which may result in denial of service or, potentially,
the execution of arbitrary code if an image with specially crafted EXIF
data is processed.

For the stable distribution (jessie), this problem has been fixed in
version 1:2.97-1+deb8u1.

For the upcoming stable distribution (stretch), this problem has been
fixed in version 1:3.00-4.

For the unstable distribution (sid), this problem has been fixed in
version 1:3.00-4.

We recommend that you upgrade your jhead packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAljemUJfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0SQaQ//e3blcNvcnuC5D2dewREv5dhBcd7wXxZ1zfm88tzfCry0j8HNOAABdRX7
OKoL4qFXW9kBSp8HlrU4oHRbfUjPOOg0vQeF64KvcAtZS5/M9tIdXTbiWaOOt+W3
SHcaESzvVbgZ9qM8WKGFhfwEb2aTJycaZEOpMYvaHKHCsjuCSrLnQEiC8EiuzVjw
efemaHOyw6QlEeSBke8WjrXPIgpcgwBiaR7COcOlJMX82CTjoQE7jzLIK9WhsztT
T3NdUg0/UWRtPyf2KzNZRQKr0ZLuNcLrWEbKh6Pj6Pxnz81LWTiaHJVI71yEJAQm
b+Ust509zRYKBXZgWvX9+6LlbRm0uFyidD9HUAJ9ASpijrMDWIFCyDTjnQX4rVNP
Cf4fVp8c4DLvvlshSpARDCWZJnopSbOVauR8Dni90MKfifHBVxzE7S9NCWbtfWzb
355NAONtY0qdSlZrreCPjQWj5awFlec2EIv9MjzPTu2Fr+UBAxTRY9YWOWfwVIOF
rEI3u1u6/2P6c1STNPOaOzLJ/DlrjbIi7fHbcXXvXsDKFLSPhv6RPRuB0AMvh6jH
CTBfaGVTJL9kS3TFN1lSQiLq6lIs31hYtOWanYVffbWt3JSFO0Us2zmUQMPzfV0M
jMVcMB9bZbLVHIi3+b2N9VSribX9QF1WYdnYzVDoP9z2Xk1wBBI=
=LkDv
-----END PGP SIGNATURE-----

Newsletter signup

Signup to our monthly newsletter and stay in touch with IT news!

Free E-books

We've got ebooks! But they're not online. :( Please give us a few days to bring downloads back.

Contact

Have something to say or just wanna drop us a line? Please keep this in mind: to spam, we reply with spam.

Contact us »