Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:15403
HistoryMay 02, 2019 - 5:00 a.m.

Sensitive Information Disclosure

2019-05-0205:00:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

EPSS

0.006

Percentile

78.3%

The libjpeg-turbo package contains a library of functions for manipulating JPEG images. It also contains simple client programs for accessing the libjpeg functions. An uninitialized memory read issue was found in the way libjpeg-turbo decoded images with missing Start Of Scan (SOS) JPEG markers or Define Huffman Table (DHT) JPEG markers. A remote attacker could create a specially crafted JPEG image that, when decoded, could possibly lead to a disclosure of potentially sensitive information. (CVE-2013-6629, CVE-2013-6630) All libjpeg-turbo users are advised to upgrade to these updated packages, which contain backported patches to correct these issues.

References