CVE-2024-2824
Severity CVSS v4.0:
Pending analysis
Type:
CWE-122
Heap-based Buffer Overflow
Publication date:
22/03/2024
Last modified:
15/04/2026
Description
A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function PrintFormatNumber of the file exif.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257711.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
7.50
Severity 2.0
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/Matthias-Wandel/jhead/files/14613084/poc.zip
- https://github.com/Matthias-Wandel/jhead/issues/84
- https://vuldb.com/?ctiid.257711
- https://vuldb.com/?id.257711
- https://github.com/Matthias-Wandel/jhead/files/14613084/poc.zip
- https://github.com/Matthias-Wandel/jhead/issues/84
- https://vuldb.com/?ctiid.257711
- https://vuldb.com/?id.257711



