Description:
This update for jhead fixes the following security issues:
- CVE-2016-3822: jhead remote attackers to execute arbitrary code or cause a
denial of service (out-of-bounds access) via crafted EXIF data (bsc#1108480).
- CVE-2018-16554: The ProcessGpsInfo function may have allowed a remote
attacker to cause a denial-of-service attack or unspecified other impact via a
malicious JPEG file, because of inconsistency between float and double in a
sprintf format string during TAG_GPS_ALT handling (bsc#1108480).