SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-6629

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of…

MEDIUM 5.0EPSS 9.73%

Does this matter?

Lower severity and a low EPSS score (9.73%). Track it; it rarely justifies an emergency change on its own.

Description

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
9.73% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
google/chrome · oracle/solaris · artifex/gpl ghostscript · libjpeg-turbo/libjpeg-turbo · fedoraproject/fedora · opensuse/opensuse · canonical/ubuntu linux · debian/debian linux · mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.