Описание
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
A flaw was found in golang. This flaw allows an attacker to craft a malformed TIFF image, which will consume a significant amount of memory when passed to DecodeConfig, leading to a denial of service.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
cert-manager Operator for Red Hat OpenShift | cert-manager/cert-manager-operator-rhel9 | Not affected | ||
Cost Management Metrics Operator | costmanagement/costmanagement-metrics-rhel8-operator | Not affected | ||
Cryostat 2 | cryostat-tech-preview/cryostat-rhel8-operator | Not affected | ||
Custom Metric Autoscaler operator for Red Hat Openshift | custom-metrics-autoscaler/custom-metrics-autoscaler-rhel8 | Not affected | ||
Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-loki-rhel8 | Not affected | ||
Migration Toolkit for Applications 6 | mta/mta-hub-rhel8 | Not affected | ||
Migration Toolkit for Containers | rhmtc/openshift-migration-velero-rhel8 | Not affected | ||
Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-controller-rhel9 | Not affected | ||
mirror registry for Red Hat OpenShift | mirror-registry-container | Not affected | ||
Node Maintenance Operator | workload-availability/node-maintenance-rhel8-operator | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
An attacker can craft a malformed TIFF image which will consume a sign ...
Uncontrolled Resource Consumption in golang.org/x/image
Уязвимость компонента DecodeConfig языка программирования Golang, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.5 Medium
CVSS3