The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2923-1 | openjdk-7 security update |
EUVD |
EUVD-2013-6431 | The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image. |
Ubuntu USN |
USN-2052-1 | Firefox vulnerabilities |
Ubuntu USN |
USN-2053-1 | Thunderbird vulnerabilities |
Ubuntu USN |
USN-2060-1 | libjpeg, libjpeg-turbo vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T17:46:22.170Z
Reserved: 2013-11-05T00:00:00
Link: CVE-2013-6629
No data.
Status : Deferred
Published: 2013-11-19T04:50:56.250
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-6629
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN