Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-36308

Опубликовано: 05 сент. 2023
Источник: debian
EPSS Низкий

Описание

disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-disintegration-imagingfixed1.6.2-3package
golang-github-disintegration-imagingno-dsabookwormpackage
golang-github-disintegration-imagingno-dsabullseyepackage
golang-github-disintegration-imagingpostponedbusterpackage

Примечания

  • https://github.com/disintegration/imaging/issues/165

EPSS

Процентиль: 6%
0.00025
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

CVSS3: 5.5
nvd
больше 2 лет назад

disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

github
больше 2 лет назад

Crash when processing crafted TIFF files

EPSS

Процентиль: 6%
0.00025
Низкий