VDB

DEBIAN-CVE-2013-6629

DEBIAN-CVE-2013-6629 PUBLISHED CVSS 8.699999809265137 HIGH

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

Risk Scores

CVSS v4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:11libjpeg-turbo0, 0, 0
Debian:12libjpeg-turbo0, 0, 0
Debian:14libjpeg-turbo0, 0, 0
Debian:13libjpeg-turbo0, 0, 0

Timeline

  • Nov 19, 2013 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›