Back to Database
Status published
Unknown
CVE-2022-41751
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by...
Vulnerability Description
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-41751
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/Matthias-Wandel/jhead
- https://github.com/Matthias-Wandel/jhead/blob/63ce118c6a59ea64ac357236a11a47aaf569d622/jhead.c#L788
- https://github.com/Matthias-Wandel/jhead/pull/57
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EG26AD7KJAY5B6L6OERSGL4FRXJE3GOB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TAVB3ZX7E5ULEXESU5NXZIAHY6CVGCHB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5NM6FET4ZNWV4EQGKZTLZFWTNVODGVOK/
- https://lists.debian.org/debian-lts-announce/2022/12/msg00004.html
- https://www.debian.org/security/2022/dsa-5294
More from jhead project
View All →CVE-2022-28550
Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(),...
Unknown
0
CVE-2021-34055
jhead 3.06 is vulnerable to Buffer Overflow via exif.c in...
Unknown
0
CVE-2021-28278
A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and...
High
7.8
CVE-2021-28277
A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and...
High
7.8
CVE-2021-28276
A Denial of Service vulnerability exists in jhead 3.04 and...
High
7.5
Affected Vendor
jhead project
View all reports →Affected Software
jhead, fedora, debian linux
Vulnerable Versions:
3.06.0.1, 35, 36, 37, 10.0, 11.0
Timeline
Official Publish:
October 17th, 2022
Last Modified:
May 13th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.