Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-6630

Опубликовано: 19 нояб. 2013
Источник: debian

Описание

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
chromium-browserfixed31.0.1650.57-1package
chromium-browserend-of-lifesqueezepackage
libjpeg-turbofixed1.3.0-3package
libjpeg6bfixed6b1-4package
libjpeg6bno-dsasqueezepackage
libjpeg6bfixed6b1-3+deb7u1wheezypackage
libjpeg8fixed8d-2package
libjpeg8no-dsasqueezepackage
libjpeg8fixed8d-1+deb7u1wheezypackage
iceweaselfixed24.2.0esr-1package
iceweaselend-of-lifesqueezepackage
icedovefixed24.2.0-1package
icedoveend-of-lifesqueezepackage
iceaperemovedpackage
iceapeend-of-lifesqueezepackage
iceapeend-of-lifewheezypackage

Примечания

  • http://packetstormsecurity.com/files/123989/IJG-jpeg6b-libjpeg-turbo-Uninitialized-Memory.html

Связанные уязвимости

ubuntu
почти 12 лет назад

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

redhat
почти 12 лет назад

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

nvd
почти 12 лет назад

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

github
больше 3 лет назад

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

oracle-oval
почти 12 лет назад

ELSA-2013-1803: libjpeg-turbo security update (MODERATE)