Inconsistent sprintf Format String in ProcessGpsInfo Function of jhead 3.00 Allows for Denial-of-Service Attack
CVE-2018-16554 · MEDIUM Severity
AV:N/AC:M/AU:N/C:P/I:P/A:P
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT handling.
Learn more about our Web Application Penetration Testing UK.