Описание
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
A flaw was found in image-size. A remote attacker can exploit this vulnerability by providing a specially crafted image buffer that contains a zero-valued size field within a recognized box-type. This malicious input can trigger an infinite loop in the JXL or HEIF image parsers, leading to a permanent block of the Node.js event loop. The consequence is a Denial of Service (DoS), causing the application to become unresponsive.
Отчет
A flaw was found in the image-size npm package. A crafted image buffer with a zero-valued size field in a recognized box-type (JXL or HEIF) can trigger an infinite loop, permanently blocking the Node.js event loop and causing a denial of service.
Меры по смягчению последствий
Upgrade to a version of image-size that validates box size fields. As a workaround, validate image inputs before passing them to image-size, rejecting files with zero-length box entries.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Gatekeeper 3 | gatekeeper/gatekeeper-rhel9 | Not affected | ||
| Red Hat Build of Podman Desktop | rh-podman-desktop.git | Not affected | ||
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9 | Not affected | ||
| Red Hat Enterprise Linux 8 | grafana | Not affected | ||
| Red Hat Enterprise Linux 8 | grafana-pcp | Not affected | ||
| Red Hat Fuse 7 | image-size | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 7 | image-size | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 8 | image-size | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | image-size | Fix deferred | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.
image-size: JXL and HEIF parsers allow denial of service through infinite loops
EPSS
6.5 Medium
CVSS3