CVE-2013-6629
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of…
Does this matter?
Lower severity and a low EPSS score (9.73%). Track it; it rarely justifies an emergency change on its own.
Description
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 9.73% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- google/chrome · oracle/solaris · artifex/gpl ghostscript · libjpeg-turbo/libjpeg-turbo · fedoraproject/fedora · opensuse/opensuse · canonical/ubuntu linux · debian/debian linux · mozilla/firefox · mozilla/seamonkey · mozilla/thunderbird
- Source
- cve@mitre.org
References
- http://advisories.mageia.org/MGASA-2013-0333.htmlThird Party Advisory
- http://archives.neohapsis.com/archives/fulldisclosure/2013-11/0080.htmlBroken Link
- http://bugs.ghostscript.com/show_bug.cgi?id=686980Issue Tracking, Vendor Advisory
- http://googlechromereleases.blogspot.com/2013/11/stable-channel-update.htmlVendor Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/123437.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124108.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/124257.htmlMailing List, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-January/125470.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00025.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00026.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00085.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00086.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00087.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00119.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00120.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00121.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00042.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140852886808946&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=140852974709252&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1803.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1804.htmlThird Party Advisory
- http://secunia.com/advisories/56175Not Applicable
- http://secunia.com/advisories/58974Not Applicable
- http://secunia.com/advisories/59058Not Applicable
- http://security.gentoo.org/glsa/glsa-201406-32.xmlThird Party Advisory
- http://support.apple.com/kb/HT6150Third Party Advisory
- http://support.apple.com/kb/HT6162Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.