Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) possibly other unspecified vectors. Reference: http://www.openwall.com/lists/oss-security/2008/10/15/6 Reference: http://www.sentex.net/~mwandel/jhead/changes.txt Reference: https://bugs.launchpad.net/ubuntu/+source/jhead/+bug/271020
jhead-2.84-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
jhead-2.84-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
This issue was addressed in: Fedora: https://admin.fedoraproject.org/updates/F8/FEDORA-2008-8941 https://admin.fedoraproject.org/updates/F9/FEDORA-2008-8928