Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q7pp-wcgr-pffx

Опубликовано: 05 сент. 2023
Источник: github
Github: Прошло ревью

Описание

Crash when processing crafted TIFF files

Disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

Пакеты

Наименование

github.com/disintegration/imaging

go
Затронутые версииВерсия исправления

<= 1.6.2

Отсутствует

EPSS

Процентиль: 6%
0.00025
Низкий

Дефекты

CWE-129

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

CVSS3: 5.5
nvd
больше 2 лет назад

disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

CVSS3: 5.5
debian
больше 2 лет назад

disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...

EPSS

Процентиль: 6%
0.00025
Низкий

Дефекты

CWE-129