jhead 'DoCommand()' Arbitrary File Deletion Vulnerability
BID:32506
Info
jhead 'DoCommand()' Arbitrary File Deletion Vulnerability
| Bugtraq ID: | 32506 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4640 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2008 12:00AM |
| Updated: | Apr 13 2015 09:38PM |
| Credit: | John Dong |
| Vulnerable: |
S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.3 Matthias Wandel jhead 2.84 Matthias Wandel jhead 2.83 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Gentoo Linux |
| Not Vulnerable: | |
Discussion
jhead 'DoCommand()' Arbitrary File Deletion Vulnerability
The 'jhead' tool is prone to a vulnerability that lets attackers delete arbitrary files in the context of the vulnerable application. This may lead to a loss of data or a denial-of-service condition.
This issue affects jhead 2.84 and prior versions.
The 'jhead' tool is prone to a vulnerability that lets attackers delete arbitrary files in the context of the vulnerable application. This may lead to a loss of data or a denial-of-service condition.
This issue affects jhead 2.84 and prior versions.
Exploit / POC
jhead 'DoCommand()' Arbitrary File Deletion Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
jhead 'DoCommand()' Arbitrary File Deletion Vulnerability
Solution:
Updates are available. Please see the references for more information.
Matthias Wandel jhead 2.83
Mandriva Linux Mandrake 2009.0 x86_64
Mandriva Linux Mandrake 2008.1 x86_64
Mandriva Linux Mandrake 2008.0 x86_64
Mandriva Linux Mandrake 2008.1
Matthias Wandel jhead 2.84
Mandriva Linux Mandrake 2008.0
Mandriva Linux Mandrake 2009.0
Solution:
Updates are available. Please see the references for more information.
Matthias Wandel jhead 2.83
-
Matthias Wandel jhead-latest.tar.gz
http://www.sentex.net/~mwandel/jhead/jhead-latest.tar.gz
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva jhead-2.86-0.1mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1 x86_64
-
Mandriva jhead-2.86-0.1mdv2008.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva jhead-2.86-0.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.1
-
Mandriva jhead-2.86-0.1mdv2008.1.i586.rpm
http://www.mandriva.com/en/download/
Matthias Wandel jhead 2.84
-
Matthias Wandel jhead-latest.tar.gz
http://www.sentex.net/~mwandel/jhead/jhead-latest.tar.gz
Mandriva Linux Mandrake 2008.0
-
Mandriva jhead-2.86-0.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0
-
Mandriva jhead-2.86-0.1mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
References
jhead 'DoCommand()' Arbitrary File Deletion Vulnerability
References:
References:
- CVE request: jhead (John Dong)
- jhead Homepage (Matthias Wandel)
- jhead: multiple security vulnerabilities (ubuntu)
- Re: CVE request: jhead (Robert Buchholz)