CVE-2022-28550
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jun 13, 2023
Updated: Jan 3, 2025
CWE ID 787
CWE ID 120
Summary
CVE-2022-28550 is a buffer overflow vulnerability affecting version 3.06 of the jhead software by Matthias-Wandel. The issue arises due to insufficient boundary checks when jhead copies strings to a stack buffer. Specifically, when the software encounters `&i` or `&o` in input, it fails to verify the buffer limits, resulting in a stack buffer overflow. This can potentially lead to arbitrary code execution or crash, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.