Описание
Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.
A flaw was found in golang.org/x/image/bmp. A remote attacker could exploit this vulnerability by providing a specially crafted paletted BMP (Bitmap) file. Decoding this file with an out-of-range palette index causes the application to panic when accessing invalid image pixels, leading to a Denial of Service (DoS). This could make the affected application unavailable to legitimate users.
Отчет
A flaw was found in golang.org/x/image/bmp. Decoding a specially crafted paletted BMP file with an out-of-range palette index causes an unrecoverable panic, resulting in denial of service. The vulnerable code is registered automatically via init() when the bmp package is imported. Versions of golang.org/x/image prior to v0.40.0 are affected.
Меры по смягчению последствий
No mitigation is available for this vulnerability.
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.
Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.
Decoding a paletted BMP file with an out-of-range palette index result ...
Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.
EPSS
6.5 Medium
CVSS3