From 70a36362e8053f3760826b4ccce860e94299c700 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sat, 22 Jun 2024 08:28:39 +0000 Subject: [ GLSA 202406-05 ] JHead: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/876247 Bug: https://bugs.gentoo.org/879801 Bug: https://bugs.gentoo.org/908519 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202406-05.xml | 48 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 glsa-202406-05.xml diff --git a/glsa-202406-05.xml b/glsa-202406-05.xml new file mode 100644 index 00000000..622d3fc8 --- /dev/null +++ b/glsa-202406-05.xml @@ -0,0 +1,48 @@ + + + + JHead: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in JHead, the worst of which may lead to arbitrary code execution. + jhead + 2024-06-22 + 2024-06-22 + 876247 + 879801 + 908519 + local + + + 3.08 + 3.08 + + + +

JHead is an EXIF JPEG header manipulation tool.

+
+ +

Multiple vulnerabilities have been discovered in JHead. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All JHead users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=media-gfx/jhead-3.08" + +
+ + CVE-2020-6624 + CVE-2020-6625 + CVE-2021-34055 + CVE-2022-28550 + CVE-2022-41751 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad