Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-6629

19
FAUCET Score

CVE-2013-6629 describes an information disclosure vulnerability in the get_sos function of libjpeg 6b and libjpeg-turbo through 1.3.0, affecting products like Google Chrome, Ghostscript, and various Linux distributions. This flaw allows remote attackers to obtain sensitive information from uninitialized memory by crafting a malicious JPEG image that duplicates component data after Start Of Scan (SOS) markers. With a CVSS score of 5.0, this vulnerability is of medium severity, requiring no authentication and having a low attack complexity, potentially leading to information exposure. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, indicating low current threat activity.

Impacted Technologies

VendorProductVersion(s)CPE
< 31.0.1650.48CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
11.3CPE matchmatch criteria
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
< 9.03CPE matchmatch criteria
cpe:2.3:a:artifex:gpl_ghostscript:*:*:*:*:*:*:*:*
< 1.3.1CPE matchmatch criteria
cpe:2.3:a:libjpeg-turbo:libjpeg-turbo:*:*:*:*:*:*:*:*
18CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
10.12%
Probability of exploitation in next 30 days
EPSS Percentile
95.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1012 is in the 94th percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (54)

microsoftpatch availablevia msrc
Product: Windows RT 8.1
microsoftpatch availablevia msrc
Product: Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 R2 for x64-based Systems Service Pack 1
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 (Server Core installation)
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 R2
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 R2 (Server Core installation)
View patch
microsoftpatch availablevia msrc
Product: Windows Vista Service Pack 2
View patch
microsoftpatch availablevia msrc
Product: Windows Vista x64 Edition Service Pack 2
View patch
microsoftpatch availablevia msrc
Product: Microsoft Silverlight 5 Developer Runtime when installed on Microsoft Windows (32-bit)
View patch
microsoftpatch availablevia msrc
Product: Microsoft Silverlight 5 Developer Runtime when installed on Microsoft Windows (x64-based)
View patch
microsoftpatch availablevia msrc
Product: Microsoft Silverlight 5 when installed on Microsoft Windows (32-bit)
View patch
microsoftpatch availablevia msrc
Product: Microsoft Silverlight 5 when installed on Microsoft Windows (x64-based)
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2016
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2016 (Server Core installation)
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1703 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1703 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Mono Framework Version 4.8.1.0
View patch
microsoftpatch availablevia msrc
Product: Mono Framework Version 5.0.0.48
View patch
microsoftpatch availablevia msrc
Product: Windows 10 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1511 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1511 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1607 for 32-bit Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1607 for x64-based Systems
View patch
microsoftpatch availablevia msrc
Product: Windows 7 for 32-bit Systems Service Pack 1
View patch
microsoftpatch availablevia msrc
Product: Windows 7 for x64-based Systems Service Pack 1
View patch
microsoftpatch availablevia msrc
Product: Windows 8.1 for 32-bit systems
View patch
microsoftpatch availablevia msrc
Product: Windows 8.1 for x64-based systems
View patch
microsoftpatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 for 32-bit Systems Service Pack 2
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 for Itanium-Based Systems Service Pack 2
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 for x64-based Systems Service Pack 2
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
View patch
mozillapatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Oracle Java for Red Hat Enterprise Linux 6Fixed in: java-1.7.0-oracle-1:1.7.0.55-1jpp.1.el6_5
View patch
redhatpatch availablevia redhat_api
Product: Oracle Java for Red Hat Enterprise Linux 6Fixed in: java-1.6.0-sun-1:1.6.0.75-1jpp.1.el6_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: libjpeg-0:6b-38
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: libjpeg-turbo-0:1.2.1-3.el6_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.4Fixed in: java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.5Fixed in: java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Satellite 5.6Fixed in: java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.7.0-oracle-1:1.7.0.55-1jpp.2.el5_10
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.7.0-ibm-1:1.7.0.7.0-1jpp.1.el5_10
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5_10
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.5.0-ibm-1:1.5.0.16.6-1jpp.1.el5_10
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.7.0-oracle-1:1.7.0.55-1jpp.1.el6_5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.7.0-ibm-1:1.7.0.7.0-1jpp.1.el6_5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el6_5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 6Fixed in: java-1.5.0-ibm-1:1.5.0.16.6-1jpp.1.el6_5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 7Fixed in: java-1.7.1-ibm-1:1.7.1.1.0-1jpp.2.el7_0
View patch
redhatpatch availablevia redhat_api
Product: Oracle Java for Red Hat Enterprise Linux 5Fixed in: java-1.7.0-oracle-1:1.7.0.55-1jpp.2.el5_10
View patch
redhatpatch availablevia redhat_api
Product: Oracle Java for Red Hat Enterprise Linux 5Fixed in: java-1.6.0-sun-1:1.6.0.75-1jpp.3.el5_10
View patch

Vendor Advisories (2)

microsoft2017-Apr/CVE-2013-6629Important

libjpeg Information Disclosure Vulnerability

Apr 11, 2017
redhatCVE-2013-6629Moderate

libjpeg: information leak (read of uninitialized memory)

Nov 12, 2013

References

advisories.mageia.org / MGASA-2013-0333.html
Third Party Advisory
archives.neohapsis.com / archives/fulldisclosure/2013-11/0080.html
Broken Link
bugs.ghostscript.com / show_bug.cgi
Issue TrackingVendor Advisory
googlechromereleases.blogspot.com / 2013/11/stable-channel-update.html
Vendor Advisory
kb.juniper.net / InfoCenter/index
Third Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2013-December/123437.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2013-December/124108.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2013-December/124257.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2014-January/125470.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2013-11/msg00025.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2013-11/msg00026.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2013-12/msg00002.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2013-12/msg00085.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2013-12/msg00086.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2013-12/msg00087.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2013-12/msg00119.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2013-12/msg00120.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2013-12/msg00121.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2014-01/msg00002.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2014-01/msg00042.html
Mailing ListThird Party Advisory
marc.info
Issue TrackingMailing ListThird Party Advisory
marc.info
Issue TrackingMailing ListThird Party Advisory
rhn.redhat.com / errata/RHSA-2013-1803.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2013-1804.html
Third Party Advisory
access.redhat.com / errata/RHSA-2014:0413
Third Party Advisory
access.redhat.com / errata/RHSA-2014:0414
Third Party Advisory
bugzilla.mozilla.org / show_bug.cgi
Issue TrackingPatchThird Party Advisory
code.google.com / p/chromium/issues/detail
Issue TrackingThird Party Advisory
secunia.com / advisories/56175
Not Applicable
secunia.com / advisories/58974
Not Applicable
secunia.com / advisories/59058
Not Applicable
security.gentoo.org / glsa/glsa-201406-32.xml
Third Party Advisory
portal.msrc.microsoft.com / en-US/security-guidance/advisory/CVE-2013-6629
PatchThird Party Advisory
security.gentoo.org / glsa/201606-03
Third Party Advisory
src.chromium.org / viewvc/chrome
PatchThird Party Advisory
support.apple.com / kb/HT6150
Third Party Advisory
support.apple.com / kb/HT6162
Third Party Advisory
support.apple.com / kb/HT6163
Third Party Advisory
ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Broken Link
debian.org / security/2013/dsa-2799
Third Party Advisory
mandriva.com / security/advisories
Broken Link
mozilla.org / security/announce/2013/mfsa2013-116.html
Third Party Advisory
oracle.com / technetwork/topics/security/bulletinapr2016-2952098.html
Third Party Advisory
oracle.com / technetwork/topics/security/cpuapr2014-1972952.html
Third Party Advisory
securityfocus.com / bid/63676
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1029470
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1029476
Broken LinkThird Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2052-1
Third Party Advisory
ubuntu.com / usn/USN-2053-1
Third Party Advisory
ubuntu.com / usn/USN-2060-1
Third Party Advisory