---
title: "CVE-2005-0406\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2005-0406?format=md
keywords: index, follow
---

# CVE-2005-0406

Publication date 14 February 2005

Last updated 17 July 2025

---

Ubuntu priority

**Negligible**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2005-0406?format=md#impact-score)

Toggle side navigation

## Description

A design flaw in image processing software that modifies JPEG images might
not modify the original EXIF thumbnail, which could lead to an information
leak of potentially sensitive visual information that had been removed from
the main JPEG image.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2005-0406?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [kees](https://launchpad.net/~kees)

very general issue, and not presently addressed.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0406)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2005-0406)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2005-0406)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2005-0406)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2005-0406>
