First published: Mon Dec 09 2013(Updated: )
The libjpeg-turbo package contains a library of functions for manipulating<br>JPEG images. It also contains simple client programs for accessing the<br>libjpeg functions.<br>An uninitialized memory read issue was found in the way libjpeg-turbo<br>decoded images with missing Start Of Scan (SOS) JPEG markers or Define<br>Huffman Table (DHT) JPEG markers. A remote attacker could create a<br>specially crafted JPEG image that, when decoded, could possibly lead to a<br>disclosure of potentially sensitive information. (CVE-2013-6629,<br>CVE-2013-6630)<br>All libjpeg-turbo users are advised to upgrade to these updated packages,<br>which contain backported patches to correct these issues.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libjpeg-turbo | <1.2.1-3.el6_5 | 1.2.1-3.el6_5 |
redhat/libjpeg-turbo | <1.2.1-3.el6_5 | 1.2.1-3.el6_5 |
redhat/libjpeg-turbo-debuginfo | <1.2.1-3.el6_5 | 1.2.1-3.el6_5 |
redhat/libjpeg-turbo-debuginfo | <1.2.1-3.el6_5 | 1.2.1-3.el6_5 |
redhat/libjpeg-turbo-devel | <1.2.1-3.el6_5 | 1.2.1-3.el6_5 |
redhat/libjpeg-turbo-devel | <1.2.1-3.el6_5 | 1.2.1-3.el6_5 |
redhat/libjpeg-turbo-static | <1.2.1-3.el6_5 | 1.2.1-3.el6_5 |
redhat/libjpeg-turbo-static | <1.2.1-3.el6_5 | 1.2.1-3.el6_5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2013:1803 is classified as moderate.
To fix RHSA-2013:1803, update the libjpeg-turbo package to version 1.2.1-3.el6_5 or a later version.
RHSA-2013:1803 addresses an uninitialized memory read issue found in libjpeg-turbo when decoding images.
The affected packages include libjpeg-turbo, libjpeg-turbo-debuginfo, libjpeg-turbo-devel, and libjpeg-turbo-static.
RHSA-2013:1803 is specifically applicable to systems running the affected versions of the Red Hat libjpeg-turbo package.