Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-6629

Опубликовано: 12 нояб. 2013
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libjpeg-turboNot affected
RHEV HypervisorlibjpegAffected
Oracle Java for Red Hat Enterprise Linux 5java-1.7.0-oracleFixedRHSA-2014:041317.04.2014
Oracle Java for Red Hat Enterprise Linux 5java-1.6.0-sunFixedRHSA-2014:041417.04.2014
Oracle Java for Red Hat Enterprise Linux 6java-1.7.0-oracleFixedRHSA-2014:041317.04.2014
Oracle Java for Red Hat Enterprise Linux 6java-1.6.0-sunFixedRHSA-2014:041417.04.2014
Red Hat Enterprise Linux 5libjpegFixedRHSA-2013:180409.12.2013
Red Hat Enterprise Linux 6libjpeg-turboFixedRHSA-2013:180309.12.2013
Red Hat Network Satellite Server v 5.4java-1.6.0-ibmFixedRHSA-2014:098229.07.2014
Red Hat Network Satellite Server v 5.5java-1.6.0-ibmFixedRHSA-2014:098229.07.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-456
https://bugzilla.redhat.com/show_bug.cgi?id=1031734libjpeg: information leak (read of uninitialized memory)

EPSS

Процентиль: 52%
0.00286
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

nvd
больше 11 лет назад

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

CVSS3: 4.7
msrc
около 8 лет назад

libjpeg Information Disclosure Vulnerability

debian
больше 11 лет назад

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-t ...

github
около 3 лет назад

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

EPSS

Процентиль: 52%
0.00286
Низкий

4.3 Medium

CVSS2