Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-6630

Опубликовано: 19 нояб. 2013
Источник: debian
EPSS Низкий

Описание

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
chromium-browserfixed31.0.1650.57-1package
chromium-browserend-of-lifesqueezepackage
libjpeg-turbofixed1.3.0-3package
libjpeg6bfixed6b1-4package
libjpeg6bno-dsasqueezepackage
libjpeg6bfixed6b1-3+deb7u1wheezypackage
libjpeg8fixed8d-2package
libjpeg8no-dsasqueezepackage
libjpeg8fixed8d-1+deb7u1wheezypackage
iceweaselfixed24.2.0esr-1package
iceweaselend-of-lifesqueezepackage
icedovefixed24.2.0-1package
icedoveend-of-lifesqueezepackage
iceaperemovedpackage
iceapeend-of-lifesqueezepackage
iceapeend-of-lifewheezypackage

Примечания

  • http://packetstormsecurity.com/files/123989/IJG-jpeg6b-libjpeg-turbo-Uninitialized-Memory.html

EPSS

Процентиль: 82%
0.01806
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

redhat
больше 11 лет назад

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

nvd
больше 11 лет назад

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

github
около 3 лет назад

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

oracle-oval
больше 11 лет назад

ELSA-2013-1803: libjpeg-turbo security update (MODERATE)

EPSS

Процентиль: 82%
0.01806
Низкий