Impact
The reported flaw is a heap-based buffer overflow in the ProcessGpsInfo routine of the WebP EXIF handler component. By tampering with the TAG_GPS_LAT and TAG_GPS_LONG arguments supplied in an image’s EXIF GPS segment, an attacker can corrupt memory on a local host, potentially causing a crash or arbitrary memory overwrite. The vulnerability is classified as CWE‑119 and CWE‑122, indicating an unbounded buffer write on the heap.
Affected Systems
The issue appears in the popular jhead utility provided by Matthias‑Wandel. Versions up to and including 3.3 are affected. No specific revision number is given beyond the 3.3 cutoff, and the project has yet to release a fix. Users running the tool for local image metadata extraction or analysis are therefore exposed to the risk.
Risk and Exploitability
The CVSS score of 4.8 places this vulnerability in the moderate range, and its exploitability is limited to local access. The EPSS score is < 1%, indicating a low probability of exploitation, and the entry is not listed in the CISA KEV catalog, which suggests that wide‑scale exploitation has not been documented. Nevertheless, any local actor capable of injecting crafted EXIF data can trigger the overflow, potentially destabilising the process that performs the metadata read. Because the problem is not remotely exploitable, the overall impact is constrained to environments where the library processes untrusted files.
OpenCVE Enrichment