Inconsistent sprintf Format String in ProcessGpsInfo Function of jhead 3.00 Allows for Denial-of-Service Attack

Inconsistent sprintf Format String in ProcessGpsInfo Function of jhead 3.00 Allows for Denial-of-Service Attack

CVE-2018-16554 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT handling.

Learn more about our Web Application Penetration Testing UK.