Information disclosure - CVE-2013-6629
Published: December 21, 2016 / Updated: April 12, 2017
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to an error in get_sos() function in jdmarker.c file within the libjpeg and libjpeg-turbo libraries when processing JPEG files. A remote attacker can create a specially crafeted JPEG file and read parts of unallocated memory on the system.
Successful exploitation of the vulnerability may allow an attacker to gain access to potentially sensitive information.
Affected software
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Oracle Solaris
Slackware Linux
Windows Server
libjpeg-turbo (Alpine package)
Mono Framework
Microsoft Silverlight
How to mitigate CVE-2013-6629
External References
Related Security Bulletins
- Multiple vulnerabilities on Oracle Solaris
- Multiple vulnerabilities in Microsoft Windows
- libjpeg Information Disclosure Vulnerability
- Slackware Linux update for libjpeg
- Red Hat update for libjpeg
- Information disclosure in libjpeg-turbo (Alpine package)
- Amazon Linux AMI update for libjpeg-turbo
- Gentoo update for libjpeg-turbo