QID 995812

Date Published: 2023-11-06

QID 995812: GO (Go) Security Update for golang.org/x/image (GHSA-j3p8-6mrq-6g7h)

A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-j3p8-6mrq-6g7h for updates and patch information.
    Vendor References

    CVEs related to QID 995812

    Software Advisories
    Advisory ID Software Component Link
    GHSA-j3p8-6mrq-6g7h golang.org/x/image URL Logo github.com/advisories/GHSA-j3p8-6mrq-6g7h