Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-29407

Опубликовано: 02 авг. 2023
Источник: debian

Описание

A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-golang-x-imagefixed0.11.0-1package
golang-golang-x-imageno-dsabookwormpackage
golang-golang-x-imageno-dsabullseyepackage
golang-golang-x-imageno-dsabusterpackage

Примечания

  • https://go.dev/issue/61581

  • https://go.dev/cl/514897

  • https://github.com/golang/image/commit/cb227cd2c919b27c6206fe0c1041a8bcc677949d (v0.10.0)

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

CVSS3: 6.5
redhat
больше 2 лет назад

A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

CVSS3: 6.5
nvd
больше 2 лет назад

A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

CVSS3: 6.5
github
больше 2 лет назад

Golang TIFF decoder vulnerable to excessive CPU consumption

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость декодера языка программирования Golang, связанная с чрезмерными итерациями, позволяющая нарушителю вызвать отказ в обслуживании