Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a small JPEG file to specify dimensions of 64250x64250 pixels, which is mishandled during an attempt to load the 'whole image' into memory.
References
Link | Resource |
---|---|
https://obsidianterminal.blogspot.com/2019/07/dos-in-imgix-cdns-image-processing.html | Third Party Advisory |
Configurations
Information
Published : 2019-07-29 12:15
Updated : 2019-08-07 07:00
NVD link : CVE-2019-13655
Mitre link : CVE-2019-13655
JSON object : View
CWE
CWE-400
Uncontrolled Resource Consumption
Products Affected
imgix
- imgix