QID 995811
Date Published: 2023-11-06
QID 995811: GO (Go) Security Update for golang.org/x/image (GHSA-x92r-3vfx-4cv3)
The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height, and encoded size) to make the decoder decode large amounts of compressed data, consuming excessive memory and CPU.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-x92r-3vfx-4cv3 for updates and patch information.
Vendor References
- GHSA-x92r-3vfx-4cv3 -
github.com/advisories/GHSA-x92r-3vfx-4cv3
CVEs related to QID 995811
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x92r-3vfx-4cv3 | golang.org/x/image |
|