Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-6629

Опубликовано: 19 нояб. 2013
Источник: debian
EPSS Низкий

Описание

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
chromium-browserfixed31.0.1650.57-1package
chromium-browserend-of-lifesqueezepackage
libjpeg-turbofixed1.3.0-3package
libjpeg6bfixed6b1-4package
libjpeg6bfixed6b1-3+deb7u1wheezypackage
libjpeg6bno-dsasqueezepackage
libjpeg8fixed8d-2package
libjpeg8no-dsasqueezepackage
libjpeg8fixed8d-1+deb7u1wheezypackage
iceweaselfixed24.2.0esr-1package
iceweaselend-of-lifesqueezepackage
icedovefixed24.2.0-1package
icedoveend-of-lifesqueezepackage
iceaperemovedpackage
iceapeend-of-lifesqueezepackage
iceapeend-of-lifewheezypackage

Примечания

  • http://packetstormsecurity.com/files/123989/IJG-jpeg6b-libjpeg-turbo-Uninitialized-Memory.html

EPSS

Процентиль: 52%
0.00286
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

redhat
больше 11 лет назад

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

nvd
больше 11 лет назад

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

CVSS3: 4.7
msrc
около 8 лет назад

libjpeg Information Disclosure Vulnerability

github
около 3 лет назад

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

EPSS

Процентиль: 52%
0.00286
Низкий
Уязвимость CVE-2013-6629