Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00531.html
https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00511.html
http://www.sentex.net/~mwandel/jhead/changes.txt
http://www.securityfocus.com/bid/31770