jhead 'DoCommand()' Arbitrary Command Execution Vulnerability
BID:31921
Info
jhead 'DoCommand()' Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 31921 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4641 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2008 12:00AM |
| Updated: | Apr 13 2015 09:57PM |
| Credit: | John Dong |
| Vulnerable: |
S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 Matthias Wandel jhead 2.84 Matthias Wandel jhead 2.83 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Gentoo Linux |
| Not Vulnerable: | |
Discussion
jhead 'DoCommand()' Arbitrary Command Execution Vulnerability
The 'jhead' tool is prone to a vulnerability that lets attackers execute arbitrary commands in the context of the vulnerable application.
This issue affects jhead 2.84 and prior versions.
The 'jhead' tool is prone to a vulnerability that lets attackers execute arbitrary commands in the context of the vulnerable application.
This issue affects jhead 2.84 and prior versions.
Exploit / POC
jhead 'DoCommand()' Arbitrary Command Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
jhead 'DoCommand()' Arbitrary Command Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Matthias Wandel jhead 2.83
Mandriva Linux Mandrake 2009.0 x86_64
Mandriva Linux Mandrake 2008.1 x86_64
Mandriva Linux Mandrake 2008.0 x86_64
Mandriva Linux Mandrake 2008.1
Matthias Wandel jhead 2.84
Mandriva Linux Mandrake 2008.0
Mandriva Linux Mandrake 2009.0
Solution:
Updates are available. Please see the references for more information.
Matthias Wandel jhead 2.83
-
Matthias Wandel jhead-latest.tar.gz
http://www.sentex.net/~mwandel/jhead/jhead-latest.tar.gz
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva jhead-2.86-0.1mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1 x86_64
-
Mandriva jhead-2.86-0.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva jhead-2.86-0.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1
-
Mandriva jhead-2.86-0.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/
Matthias Wandel jhead 2.84
-
Matthias Wandel jhead-latest.tar.gz
http://www.sentex.net/~mwandel/jhead/jhead-latest.tar.gz
Mandriva Linux Mandrake 2008.0
-
Mandriva jhead-2.86-0.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0
-
Mandriva jhead-2.86-0.1mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
References
jhead 'DoCommand()' Arbitrary Command Execution Vulnerability
References:
References:
- CVE request: jhead (John Dong)
- jhead Homepage (Matthias Wandel)
- jhead: multiple security vulnerabilities (ubuntu)
- Re: CVE request: jhead (Robert Buchholz)