CVE-2021-3496 describes a heap-based buffer overflow vulnerability in jhead version 3.06, specifically within the Get16u() function in exif.c, triggered by processing a specially crafted file. This high-severity vulnerability (CVSS 7.8) can lead to complete compromise of confidentiality, integrity, and availability if an attacker convinces a user to open a malicious file. While no active exploitation, public exploit code, or significant community discussion has been observed, the potential impact warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.06CPE matchmatch criteria | cpe:2.3:a:jhead_project:jhead:3.06:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.