Описание
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-golang-x-image | fixed | 0.38.0-1 | package | |
| golang-golang-x-image | no-dsa | trixie | package | |
| golang-golang-x-image | no-dsa | bookworm | package | |
| golang-golang-x-image | postponed | bullseye | package |
Примечания
https://github.com/golang/go/issues/78267
Fixed by: https://github.com/golang/image/commit/23ae9ed61c1d3343fb95015810f62dcbf444976e (v0.38.0)
EPSS
Связанные уязвимости
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
Уязвимость библиотеки golang.org/x/image/tiff языка программирования Go, позволяющая нарушителю выполнить произвольный код
EPSS