Описание
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-golang-x-image | fixed | 0.45.0-1 | package | |
| golang-golang-x-image | no-dsa | trixie | package | |
| golang-golang-x-image | postponed | bookworm | package | |
| golang-golang-x-image | postponed | bullseye | package |
Примечания
https://github.com/golang/go/issues/80069
Fixed by: https://github.com/golang/image/commit/981eaa05a5065f5dd09c3139029c0d7dbda956d8 (v0.45.0)
Связанные уязвимости
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.