Уязвимость утечки конфиденциальной информации в libjpeg и libjpeg-turbo через некорректную обработку данных сегментов JPEG
Описание
Функция get_sos
в jdmarker.c
в (1) libjpeg
версии 6b и (2) libjpeg-turbo
до версии 1.3.0, как используется в Google Chrome до версии 31.0.1650.48, Ghostscript и других продуктах, не проверяет определенные дублирования данных компонентов во время чтения сегментов, следующих за маркером Start Of Scan (SOS) в JPEG, что позволяет злоумышленникам получить конфиденциальную информацию из неинициализированных областей памяти через специально созданное JPEG-изображение.
Затронутые версии ПО
- libjpeg 6b
- libjpeg-turbo до версии 1.3.0
- Google Chrome < 31.0.1650.48
- Ghostscript
- Другие продукты, использующие данные библиотеки
Тип уязвимости
Утечка конфиденциальной информации
Ссылки
- Third Party Advisory
- Broken Link
- Issue TrackingVendor Advisory
- Vendor Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
Одно из
Одно из
EPSS
5 Medium
CVSS2
Дефекты
Связанные уязвимости
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-t ...
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.
EPSS
5 Medium
CVSS2