The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.
2013-11-19T04:50:56.267
2025-04-11T00:51:21.963
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | chrome | ≤ 31.0.1650.47 | Yes | |
| Application | chrome | 31.0.1650.0 | Yes | |
| Application | chrome | 31.0.1650.2 | Yes | |
| Application | chrome | 31.0.1650.3 | Yes | |
| Application | chrome | 31.0.1650.4 | Yes | |
| Application | chrome | 31.0.1650.5 | Yes | |
| Application | chrome | 31.0.1650.6 | Yes | |
| Application | chrome | 31.0.1650.7 | Yes | |
| Application | chrome | 31.0.1650.8 | Yes | |
| Application | chrome | 31.0.1650.9 | Yes | |
| Application | chrome | 31.0.1650.10 | Yes | |
| Application | chrome | 31.0.1650.11 | Yes | |
| Application | chrome | 31.0.1650.12 | Yes | |
| Application | chrome | 31.0.1650.13 | Yes | |
| Application | chrome | 31.0.1650.14 | Yes | |
| Application | chrome | 31.0.1650.15 | Yes | |
| Application | chrome | 31.0.1650.16 | Yes | |
| Application | chrome | 31.0.1650.17 | Yes | |
| Application | chrome | 31.0.1650.18 | Yes | |
| Application | chrome | 31.0.1650.19 | Yes | |
| Application | chrome | 31.0.1650.20 | Yes | |
| Application | chrome | 31.0.1650.22 | Yes | |
| Application | chrome | 31.0.1650.23 | Yes | |
| Application | chrome | 31.0.1650.25 | Yes | |
| Application | chrome | 31.0.1650.26 | Yes | |
| Application | chrome | 31.0.1650.27 | Yes | |
| Application | chrome | 31.0.1650.28 | Yes | |
| Application | chrome | 31.0.1650.29 | Yes | |
| Application | chrome | 31.0.1650.30 | Yes | |
| Application | chrome | 31.0.1650.31 | Yes | |
| Application | chrome | 31.0.1650.32 | Yes | |
| Application | chrome | 31.0.1650.33 | Yes | |
| Application | chrome | 31.0.1650.34 | Yes | |
| Application | chrome | 31.0.1650.35 | Yes | |
| Application | chrome | 31.0.1650.36 | Yes | |
| Application | chrome | 31.0.1650.37 | Yes | |
| Application | chrome | 31.0.1650.38 | Yes | |
| Application | chrome | 31.0.1650.39 | Yes | |
| Application | chrome | 31.0.1650.41 | Yes | |
| Application | chrome | 31.0.1650.42 | Yes | |
| Application | chrome | 31.0.1650.43 | Yes | |
| Application | chrome | 31.0.1650.44 | Yes | |
| Application | chrome | 31.0.1650.45 | Yes | |
| Application | chrome | 31.0.1650.46 | Yes |