CVE-2013-6629
EUVD-2013-643119.11.2013, 04:50
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| chrome | 𝑥 < 31.0.1650.48 | |
| oracle | solaris | 11.3 |
| artifex | gpl_ghostscript | 𝑥 < 9.03 |
| libjpeg-turbo | libjpeg-turbo | 𝑥 < 1.3.1 |
| opensuse | opensuse | 12.2 |
| opensuse | opensuse | 12.3 |
| opensuse | opensuse | 13.1 |
| canonical | ubuntu_linux | 10.04 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
| canonical | ubuntu_linux | 13.04 |
| canonical | ubuntu_linux | 13.10 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| mozilla | firefox | 𝑥 < 24.2 |
| mozilla | firefox | 𝑥 < 26.0 |
| mozilla | seamonkey | 𝑥 < 2.23 |
| mozilla | thunderbird | 𝑥 < 24.2.0 |
𝑥
= Vulnerable software versions
Windows Releases
Platform | Version | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Windows 10 |
| ||||||||
| Windows 7 |
| ||||||||
| Windows 8.1 |
| ||||||||
| Windows RT 8.1 |
| ||||||||
| Windows Server 2008 |
| ||||||||
| Windows Server 2008 R2 |
| ||||||||
| Windows Server 2012 |
| ||||||||
| Windows Server 2012 R2 |
| ||||||||
| Windows Server 2016 |
| ||||||||
| Windows Vista |
|
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||||
| libjpeg-turbo |
| ||||||||||
| libjpeg6b |
| ||||||||||
| openjdk-7 |
| ||||||||||
| thunderbird |
|
Common Weakness Enumeration
References