Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for jhead ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0371-1 Rating: moderate References: #1207150 Cross-References: CVE-2022-41751 CVSS scores: CVE-2022-41751 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for jhead fixes the following issues: - Fixed autorotation problem caused by CVE-2022-41751 patch. [boo#1207150] Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-371=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): jhead-3.06.0.1-bp155.5.3.1 References: https://www.suse.com/security/cve/CVE-2022-41751.html https://bugzilla.suse.com/1207150 . Critical patch available for jhead on openSUSE; addresses a significant security flaw with detailed installation guidelines included.. openSUSE Update,jhead Security Patch,jhead Vulnerability Fix,Software Update. . LinuxSecurity.com Team
Several security issues were fixed in Jhead.. =========================================================================Ubuntu Security Notice USN-6098-1 May 23, 2023 Jhead vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Jhead. Software Description: - jhead: Manipulate the non-image part of Exif compliant JPEG files Details: It was discovered that Jhead did not properly handle certain crafted images while processing the JFIF markers. An attacker could cause Jhead to crash. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2019-19035) It was discovered that Jhead did not properly handle certain crafted images while processing longitude tags. An attacker could cause Jhead to crash. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-1010301) It was discovered that Jhead did not properly handle certain crafted images while processing IPTC data. An attacker could cause Jhead to crash. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-1010302) Binbin Li discovered that Jhead did not properly handle certain crafted images while processing the DQT data. An attacker could cause Jhead to crash. (CVE-2020-6624) Binbin Li discovered that Jhead did not properly handle certain crafted images while processing longitude data. An attacker could cause Jhead to crash. (CVE-2020-6625) Feng Zhao Yang discovered that Jhead did not properly handle certain crafted images while reading JPEG sections. An attacker could cause Jhead to crash. (CVE-2020-26208) It was discovered that Jhead did not properly handle certain crafted images while processing Canon images. An attacker could cause Jhead tocrash. (CVE-2021-28276) It was discovered that Jhead did not properly handle certain crafted images when removing a certain type of sections. An attacker could cause Jhead to crash. (CVE-2021-28278) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: jhead 1:3.04-1ubuntu0.1 Ubuntu 18.04 LTS: jhead 1:3.00-8~ubuntu0.1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): jhead 1:3.00-4+deb9u1ubuntu0.1~esm1 Ubuntu 14.04 LTS (Available with Ubuntu Pro): jhead 1:2.97-1+deb8u2ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6098-1 CVE-2019-1010301, CVE-2019-1010302, CVE-2019-19035, CVE-2020-26208, CVE-2020-6624, CVE-2020-6625, CVE-2021-28276, CVE-2021-28278 Package Information: https://launchpad.net/ubuntu/+source/jhead/1:3.04-1ubuntu0.1 https://launchpad.net/ubuntu/+source/jhead/1:3.00-8~ubuntu0.1 . Several Jhead vulnerabilities identified for Ubuntu versions 14.04 through 20.04 LTS may lead to system instability stemming from manipulated image files.. Ubuntu Security Notice, Jhead Fixes, Software Update Instructions. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for jhead ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0054-1 Rating: moderate References: #1207150 Cross-References: CVE-2022-41751 CVSS scores: CVE-2022-41751 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for jhead fixes the following issues: - Fixed autorotation problem caused by CVE-2022-41751 patch. [boo#1207150] Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-54=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): jhead-3.06.0.1-bp154.2.9.1 References: https://www.suse.com/security/cve/CVE-2022-41751.html https://bugzilla.suse.com/1207150 . This enhancement for jhead on openSUSE mitigates a moderate risk by resolving a documented concern.. openSUSE Security Update,jhead Update,System Security Fix,OpenSUSE Threat. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for jhead ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10203-1 Rating: important References: #1205167 Cross-References: CVE-2021-34055 CVSS scores: CVE-2021-34055 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for jhead fixes the following issues: * CVE-2021-34055: Fix out of bounds write in ClearOrientation() due to unchecked error (boo#1205167) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-10203=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): jhead-3.00-bp153.3.6.1 References: https://www.suse.com/security/cve/CVE-2021-34055.html https://bugzilla.suse.com/1205167 . A significant patch for jhead resolves a crucial vulnerability (CVE-2021-34055) affecting openSUSE users. Discover further details.. OpenSUSE Security Update, Jhead Vulnerability, Important Patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for jhead ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10202-1 Rating: important References: #1205167 Cross-References: CVE-2021-34055 CVSS scores: CVE-2021-34055 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for jhead fixes the following issues: * CVE-2021-34055: Fix out of bounds write in ClearOrientation() due to unchecked error (boo#1205167) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10202=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): jhead-3.06.0.1-bp154.2.6.1 References: https://www.suse.com/security/cve/CVE-2021-34055.html https://bugzilla.suse.com/1205167 . Important: jhead has received an update addressing the critical security vulnerability CVE-2021-34055 in openSUSE Backports SLE-15-SP4. Please ensure to install the update immediately!. openSUSE Patch, jhead Update, CVE-2021-34055 Fix. . Severity: Important. LinuxSecurity.com Team
added patches to fix CVE-2022-41751. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-628829f0e6 2022-11-10 22:04:44.631614 --------------------------------------------------------------------------------Name : jhead Product : Fedora 37 Version : 3.06.0.1 Release : 5.fc37 URL : https://www.sentex.ca/~mwandel/jhead/ Summary : Tool for displaying EXIF data embedded in JPEG images Description : Jhead displays and manipulates the non-image portions of EXIF formatted JPEG images, such as the images produced by most digital cameras. --------------------------------------------------------------------------------Update Information: added patches to fix CVE-2022-41751 --------------------------------------------------------------------------------ChangeLog: * Tue Oct 18 2022 Adrian Reber - 3.06.0.1-5 - added patches to fix CVE-2022-41751 --------------------------------------------------------------------------------References: [ 1 ] Bug #2135591 - CVE-2022-41751 jhead: arbitrary OS commands by placing them in a JPEG filename https://bugzilla.redhat.com/show_bug.cgi?id=2135591 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-628829f0e6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for jhead ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10179-1 Rating: important References: #1204409 Cross-References: CVE-2022-41751 CVSS scores: CVE-2022-41751 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for jhead fixes the following issues: - CVE-2022-41751: Fixed shell injection via filenames (boo#1204409) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10179=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): jhead-3.06.0.1-bp154.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-41751.html https://bugzilla.suse.com/1204409 . Critical openSUSE Security Patch released for jhead targeting security flaws. Prompt action advised for all users.. openSUSE Security Update,jhead software,important update,shell injection fix. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities have been found in JHead, the worst of which could result in denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202210-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: JHead: Multiple Vulnerabilities Date: October 31, 2022 Bugs: #730746 ID: 202210-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in JHead, the worst of which could result in denial of service. Background ========= JHead is an EXIF JPEG header manipulation tool. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/jhead < 3.06.0.1 > = 3.06.0.1 Description ========== Multiple vulnerabilities have been discovered in JHead. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All JHead users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/jhead-3.06.0.1" References ========= [ 1 ] CVE-2021-3496 https://nvd.nist.gov/vuln/detail/CVE-2021-3496 [ 2 ] CVE-2021-28275 https://nvd.nist.gov/vuln/detail/CVE-2021-28275 [ 3 ] CVE-2021-28276 https://nvd.nist.gov/vuln/detail/CVE-2021-28276 [ 4 ] CVE-2021-28277 https://nvd.nist.gov/vuln/detail/CVE-2021-28277 [ 5 ] CVE-2021-28278 https://nvd.nist.gov/vuln/detail/CVE-2021-28278 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202210-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.