An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
References
Link | Resource |
---|---|
https://go.dev/cl/468195 | Patch |
https://go.dev/issue/58003 | Issue Tracking |
https://groups.google.com/g/golang-announce/c/ag-FiyjlD5o | Mailing List Vendor Advisory |
https://pkg.go.dev/vuln/GO-2023-1572 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-02-28 10:15
Updated : 2023-03-09 16:15
NVD link : CVE-2022-41727
Mitre link : CVE-2022-41727
JSON object : View
CWE
CWE-400
Uncontrolled Resource Consumption
Products Affected
golang
- tiff
- image