Описание
Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.
A flaw was found in golang.org/x/image. A remote attacker could exploit this vulnerability by providing a specially crafted WEBP image with an invalid, large size. This could cause the application to panic and crash on 32-bit platforms, leading to a Denial of Service (DoS).
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Serverless | openshift-serverless-1/kn-plugin-event-sender-rhel9 | Affected | ||
| OpenShift Service Mesh 2 | openshift-golang-builder-container | Not affected | ||
| OpenShift Service Mesh 2 | openshift-service-mesh/istio-rhel8-operator | Not affected | ||
| OpenShift Service Mesh 3 | openshift-golang-builder-container | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel9 | Affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/volsync-rhel9 | Will not fix | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform/platform-operator-bundle | Not affected | ||
| Red Hat Enterprise Linux 10 | golang | Not affected | ||
| Red Hat Enterprise Linux 8 | go-toolset:rhel8/golang | Will not fix | ||
| Red Hat Enterprise Linux 9 | golang | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.
Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.
Parsing a WEBP image with an invalid, large size panics on 32-bit plat ...
Уязвимость пакета golang-x-image языка программирования Go, связанная с некорректным вычислением, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.5 Medium
CVSS3