Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-44p7-9xx4-hf2g

Опубликовано: 25 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

Пакеты

Наименование

golang.org/x/image

go
Затронутые версииВерсия исправления

< 0.38.0

0.38.0

EPSS

Процентиль: 25%
0.00328
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-434
CWE-770

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

CVSS3: 6.5
redhat
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

CVSS3: 5.3
nvd
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

CVSS3: 5.3
debian
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to ...

CVSS3: 5.3
fstec
4 месяца назад

Уязвимость библиотеки golang.org/x/image/tiff языка программирования Go, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 25%
0.00328
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-434
CWE-770