Security update for jhead
This update for jhead fixes the following security issues:
- CVE-2016-3822: jhead remote attackers to execute arbitrary code or cause a
denial of service (out-of-bounds access) via crafted EXIF data (bsc#1108480).
- CVE-2018-16554: The ProcessGpsInfo function may have allowed a remote
attacker to cause a denial-of-service attack or unspecified other impact via a
malicious JPEG file, because of inconsistency between float and double in a
sprintf format string during TAG_GPS_ALT handling (bsc#1108480).
- Submitted by Stanislav Brabec (sbrabec)
Fixed bugs
bnc#1108480
VUL-1: CVE-2018-16554: jhead: Interger overflow while running jhead