Solution
Please Install the Updated Packages.
Insight
The libjpeg-turbo package contains a library of functions for manipulating JPEG images. It also contains simple client programs for accessing the libjpeg functions.
An uninitialized memory read issue was found in the way libjpeg-turbo decoded images with missing Start Of Scan (SOS) JPEG markers or Define Huffman Table (DHT) JPEG markers. A remote attacker could create a specially crafted JPEG image that, when decoded, could possibly lead to a disclosure of potentially sensitive information. (CVE-2013-6629, CVE-2013-6630)
All libjpeg-turbo users are advised to upgrade to these updated packages, which contain backported patches to correct these issues.
Affected
libjpeg-turbo on CentOS 6
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2013-6629, CVE-2013-6630 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities