Name | CVE-2013-6630 |
Description | The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-2799-1 |
Debian Bugs | 729867, 729873 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
chromium-browser (PTS) | jessie, jessie (lts) | 57.0.2987.98-1~deb8u1 | fixed |
stretch (security), stretch (lts), stretch | 71.0.3578.80-1~deb9u1 | fixed | |
icedove (PTS) | jessie | 1:52.3.0-4~deb8u2 | fixed |
libjpeg-turbo (PTS) | jessie, jessie (lts) | 1:1.3.1-12+deb8u3 | fixed |
stretch (security) | 1:1.5.1-2+deb9u2 | fixed | |
stretch (lts), stretch | 1:1.5.1-2+deb9u3 | fixed | |
buster | 1:1.5.2-2+deb10u1 | fixed | |
bullseye | 1:2.0.6-4 | fixed | |
bookworm | 1:2.1.5-2 | fixed | |
sid, trixie | 1:2.1.5-3 | fixed | |
libjpeg6b (PTS) | sid | 1:6b2-4 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
chromium-browser | source | squeeze | (unfixed) | end-of-life | ||
chromium-browser | source | wheezy | 31.0.1650.57-1~deb7u1 | DSA-2799-1 | ||
chromium-browser | source | (unstable) | 31.0.1650.57-1 | |||
iceape | source | squeeze | (unfixed) | end-of-life | ||
iceape | source | wheezy | (unfixed) | end-of-life | ||
iceape | source | (unstable) | (unfixed) | |||
icedove | source | squeeze | (unfixed) | end-of-life | ||
icedove | source | (unstable) | 24.2.0-1 | |||
iceweasel | source | squeeze | (unfixed) | end-of-life | ||
iceweasel | source | (unstable) | 24.2.0esr-1 | |||
libjpeg-turbo | source | (unstable) | 1.3.0-3 | low | 729873 | |
libjpeg6b | source | wheezy | 6b1-3+deb7u1 | |||
libjpeg6b | source | (unstable) | 6b1-4 | low | 729867 | |
libjpeg8 | source | wheezy | 8d-1+deb7u1 | |||
libjpeg8 | source | (unstable) | 8d-2 | low | 729867 |
[squeeze] - libjpeg6b <no-dsa> (Minor issue)
[squeeze] - libjpeg8 <no-dsa> (Minor issue)
http://packetstormsecurity.com/files/123989/IJG-jpeg6b-libjpeg-turbo-Uninitialized-Memory.html