5

CVE-2013-6629

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GoogleChrome Version < 31.0.1650.48
OracleSolaris Version11.3
ArtifexGpl Ghostscript Version < 9.03
Libjpeg-turboLibjpeg-turbo Version < 1.3.1
FedoraprojectFedora Version18
FedoraprojectFedora Version19
FedoraprojectFedora Version20
OpensuseOpensuse Version12.2
OpensuseOpensuse Version12.3
OpensuseOpensuse Version13.1
CanonicalUbuntu Linux Version10.04 SwEdition-
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version12.10
CanonicalUbuntu Linux Version13.04
CanonicalUbuntu Linux Version13.10
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
MozillaFirefox Version < 26.0
MozillaFirefox ESR Version < 24.2
MozillaSeamonkey Version < 2.23
MozillaThunderbird Version < 24.2.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.435
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://marc.info/?l=bugtraq&m=140852886808946&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://marc.info/?l=bugtraq&m=140852974709252&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://www.securityfocus.com/bid/63676
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1029470
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1029476
Third Party Advisory
Broken Link
VDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=891693
Patch
Third Party Advisory
Issue Tracking