Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q675-qj96-32m9

Опубликовано: 02 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

golang.org/x/image/tiff has excessive resource consumption in PackBits decompression

The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.

Пакеты

Наименование

golang.org/x/image

go
Затронутые версииВерсия исправления

< 0.41.0

0.41.0

EPSS

Процентиль: 28%
0.00353
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.

CVSS3: 6.5
redhat
2 месяца назад

The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.

CVSS3: 7.5
nvd
2 месяца назад

The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded size) to make the decoder decode large amounts of compressed data.

CVSS3: 7.5
debian
2 месяца назад

The TIFF decoder does not place a limit on the size of PackBits-compre ...

EPSS

Процентиль: 28%
0.00353
Низкий

7.5 High

CVSS3

Дефекты

CWE-770