CVE-2013-6630

NameCVE-2013-6630
DescriptionThe get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as ...
SourceCVE (at NVD; oss-sec, OSVDB, EDB, Red Hat, Ubuntu, Gentoo, SuSE, more)
ReferencesDSA-2799-1
Debian Bugs729867, 729873
Debian/oldstablepackages libjpeg6b, libjpeg8 are vulnerable.
Debian/stablepackages icedove, iceweasel, libjpeg6b, libjpeg8 are vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chromium-browser (PTS)squeeze, squeeze (security)6.0.472.63~r59945-5+squeeze6fixed
wheezy31.0.1650.63-1~deb7u1fixed
jessie33.0.1750.152-1fixed
wheezy (security)34.0.1847.116-1~deb7u1fixed
sid34.0.1847.116-2fixed
iceape (PTS)squeeze (security)2.0.11-17fixed
icedove (PTS)squeeze, squeeze (security)3.0.11-1+squeeze15fixed
wheezy10.0.12-1vulnerable
wheezy (security)24.4.0-1~deb7u1fixed
jessie, sid24.4.0-1fixed
iceweasel (PTS)squeeze, squeeze (security)3.5.16-20fixed
wheezy17.0.10esr-1~deb7u1vulnerable
wheezy (security)24.4.0esr-1~deb7u2fixed
jessie, sid24.4.0esr-1fixed
libjpeg-turbo (PTS)jessie, sid1.3.0-4fixed
libjpeg6b (PTS)squeeze6b1-1vulnerable
wheezy6b1-3vulnerable
jessie, sid6b1-4fixed
libjpeg8 (PTS)squeeze8b-1vulnerable
wheezy8d-1vulnerable
jessie, sid8d-2fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chromium-browsersource(unstable)31.0.1650.57-1
chromium-browsersourcesqueeze(not affected)
chromium-browsersourcewheezy31.0.1650.57-1~deb7u1DSA-2799-1
iceapesource(unstable)(unfixed)
iceapesourcesqueeze(not affected)
iceapesourcewheezy(not affected)
icedovesource(unstable)24.2.0-1
icedovesourcesqueeze(not affected)
iceweaselsource(unstable)24.2.0esr-1
iceweaselsourcesqueeze(not affected)
libjpeg-turbosource(unstable)1.3.0-3low729873
libjpeg6bsource(unstable)6b1-4low729867
libjpeg8source(unstable)8d-2low729867

Notes

[squeeze] - libjpeg6b <no-dsa> (Minor issue)
[wheezy] - libjpeg6b <no-dsa> (Minor issue)
[squeeze] - libjpeg8 <no-dsa> (Minor issue)
[wheezy] - libjpeg8 <no-dsa> (Minor issue)
http://packetstormsecurity.com/files/123989/IJG-jpeg6b-libjpeg-turbo-Uninitialized-Memory.html

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Source (SVN)