Описание
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
A flaw was found in golang.org/x/image/tiff. A remote attacker could exploit this vulnerability by providing a maliciously crafted Tagged Image File Format (TIFF) file. This could cause the image decoding process to attempt to allocate up to 4 gigabytes (GiB) of memory. The excessive resource consumption or an out-of-memory error would lead to a Denial of Service (DoS) condition.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 4 | cryostat/cryostat-storage-rhel9 | Fix deferred | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/cluster-logging-rhel9-operator | Fix deferred | ||
| OpenShift Service Mesh 2 | openshift-golang-builder-container | Fix deferred | ||
| OpenShift Service Mesh 3 | openshift-golang-builder-container | Fix deferred | ||
| Red Hat Enterprise Linux 10 | golang | Fix deferred | ||
| Red Hat Enterprise Linux 8 | go-toolset:rhel8/golang | Fix deferred | ||
| Red Hat Enterprise Linux 9 | golang | Fix deferred | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | golang | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-tests-rhel9 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift-golang-builder-container | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
A maliciously crafted TIFF file can cause image decoding to attempt to ...
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
Уязвимость библиотеки golang.org/x/image/tiff языка программирования Go, позволяющая нарушителю выполнить произвольный код
EPSS
6.5 Medium
CVSS3