Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-6629

Опубликовано: 19 нояб. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

РелизСтатусПримечание
devel

not-affected

lucid

ignored

end of life
precise

released

26.0+build2-0ubuntu0.12.04.2
quantal

released

26.0+build2-0ubuntu0.12.10.2
raring

released

26.0+build2-0ubuntu0.13.04.2
saucy

released

26.0+build2-0ubuntu0.13.10.2
upstream

released

26.0

Показывать по

РелизСтатусПримечание
devel

released

1.3.0-0ubuntu2
lucid

DNE

precise

released

1.1.90+svn733-0ubuntu4.3
quantal

released

1.2.1-0ubuntu2.12.10.1
raring

released

1.2.1-0ubuntu2.13.04.1
saucy

released

1.3.0-0ubuntu1.1
upstream

needed

Показывать по

РелизСтатусПримечание
devel

not-affected

6b1-4ubuntu1
lucid

released

6b-15ubuntu1.1
precise

released

6b1-2ubuntu1.1
quantal

released

6b1-2ubuntu2.1
raring

released

6b1-3ubuntu1.13.04.1
saucy

released

6b1-3ubuntu1.13.10.1
upstream

released

6b1-4

Показывать по

РелизСтатусПримечание
devel

ignored

uses system libjpeg6b
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [uses system libjpeg6b]]
lucid

DNE

precise

ignored

end of life
quantal

ignored

end of life
saucy

ignored

end of life
trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [uses system libjpeg6b]
upstream

released

7u55-2.4.7-1

Показывать по

РелизСтатусПримечание
devel

released

1:24.2.0+build1-0ubuntu1
lucid

ignored

end of life
precise

released

1:24.2.0+build1-0ubuntu0.12.04.1
quantal

released

1:24.2.0+build1-0ubuntu0.12.10.1
raring

released

1:24.2.0+build1-0ubuntu0.13.04.1
saucy

released

1:24.2.0+build1-0ubuntu0.13.10.1
upstream

released

24.2.0

Показывать по

EPSS

Процентиль: 52%
0.00286
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

nvd
больше 11 лет назад

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

CVSS3: 4.7
msrc
около 8 лет назад

libjpeg Information Disclosure Vulnerability

debian
больше 11 лет назад

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-t ...

github
около 3 лет назад

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

EPSS

Процентиль: 52%
0.00286
Низкий

5 Medium

CVSS2