Impact
A vulnerability exists in the Get16u routine of jhead’s exif.c module, which performs an out‑of‑bounds read during EXIF parsing. The flaw allows a local user to trigger a buffer overread that can expose arbitrary data residing in memory, potentially leaking credentials or confidential information. The weakness is classified as CWE‑119 (Improper Restriction of Operations within the Bounds of a Buffer) and CWE‑125 (Out‑of‑Bounds Read).
Affected Systems
The risk applies to the Matthias‑Wandel jhead utility for EXIF parsing, versions up to and including 3.3. These versions read metadata from image files locally and are commonly invoked by users or automated scripts on the host system.
Risk and Exploitability
The CVSS score of 4.8 indicates a medium level of risk. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, implying that remote exploitation is unlikely and the risk is confined to systems where a local attacker can execute the program. Public proof‑of‑concept code is available, so an unpatched installation that processes untrusted image files could suffer data leakage or potential crashes.
OpenCVE Enrichment