CVE-2013-6629
Publication date 18 November 2013
Last updated 24 July 2024
Ubuntu priority
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.
Status
Package | Ubuntu Release | Status |
---|---|---|
firefox | ||
libjpeg-turbo | ||
libjpeg6b | ||
openjdk-7 | 14.04 LTS trusty | Not in release |
thunderbird | ||
Notes
seth-arnold
Michal suggests libjpeg6b will not be updated from upstream
mdeslaur
upstream bug and proposed patch is ancient. Chromium contains a patch.
jdstrand
openjdk uses system jpeg
Patch details
References
Related Ubuntu Security Notices (USN)
- USN-2052-1
- Firefox vulnerabilities
- 11 December 2013
- USN-2060-1
- libjpeg, libjpeg-turbo vulnerabilities
- 19 December 2013
- USN-2053-1
- Thunderbird vulnerabilities
- 11 December 2013