CVE-2018-16554: Jhead Project Jhead

High severity, CVSS 7.8. EPSS: 1.8% chance of exploitation in the next 30 days.

The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT handling.

Affected products

Published 2018-09-16. Last modified 2026-06-17.