First published: Mon Dec 09 2013(Updated: )
The libjpeg package contains a library of functions for manipulating JPEG<br>images. It also contains simple client programs for accessing the<br>libjpeg functions.<br>An uninitialized memory read issue was found in the way libjpeg decoded<br>images with missing Start Of Scan (SOS) JPEG markers. A remote attacker<br>could create a specially crafted JPEG image that, when decoded, could<br>possibly lead to a disclosure of potentially sensitive information.<br>(CVE-2013-6629)<br>All libjpeg users are advised to upgrade to this updated package, which<br>contains a backported patch to correct this issue.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2013:1804 is classified as moderate.
To fix RHSA-2013:1804, update the libjpeg package to the latest version as provided by your system's package manager.
RHSA-2013:1804 addresses an uninitialized memory read issue in the libjpeg library when decoding images with missing Start Of Scan (SOS) segments.
No, RHSA-2013:1804 is not considered a critical vulnerability; it has a moderate impact.
All users and systems utilizing the vulnerable libjpeg package are affected by RHSA-2013:1804.