High severity7.8NVD Advisory· Published Apr 22, 2021· Updated Jun 17, 2026
CVE-2021-3496
CVE-2021-3496
Description
A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:jhead_project:jhead:3.06:*:*:*:*:*:*:*
- jhead/jheaddescription
- osv-coords3 versionspkg:rpm/opensuse/jhead&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/jhead&distro=openSUSE%20Tumbleweedpkg:rpm/suse/jhead&distro=SUSE%20Package%20Hub%2015%20SP2
< 3.00-lp152.7.3.1+ 2 more
- (no CPE)range: < 3.00-lp152.7.3.1
- (no CPE)range: < 3.06.0.1-1.3
- (no CPE)range: < 3.00-bp152.4.3.1
Patches
Vulnerability mechanics
References
3- github.com/Matthias-Wandel/jhead/issues/33nvdExploitPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- security.gentoo.org/glsa/202210-17nvdThird Party Advisory
News mentions
0No linked articles in our index yet.