golang-github-disintegration-imaging: CVE-2023-36308

Related Vulnerabilities: CVE-2023-36308  

Debian Bug report logs - #1069062
golang-github-disintegration-imaging: CVE-2023-36308

Reported by: Maytham Alsudany <maytha8thedev@gmail.com>

Date: Mon, 15 Apr 2024 18:33:01 UTC

Severity: normal

Tags: pending, security, upstream

Forwarded to https://github.com/disintegration/imaging/issues/165

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Debian Go Packaging Team <team+pkg-go@tracker.debian.org>:
Bug#1069062; Package golang-github-disintegration-imaging. (Mon, 15 Apr 2024 18:33:03 GMT) (full text, mbox, link).


Acknowledgement sent to Maytham Alsudany <maytha8thedev@gmail.com>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Debian Go Packaging Team <team+pkg-go@tracker.debian.org>. (Mon, 15 Apr 2024 18:33:03 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Maytham Alsudany <maytha8thedev@gmail.com>
To: submit@bugs.debian.org
Subject: golang-github-disintegration-imaging: CVE-2023-36308
Date: Mon, 15 Apr 2024 21:30:20 +0300
[Message part 1 (text/plain, inline)]
Package: golang-github-disintegration-imaging
X-Debbugs-CC: team@security.debian.org
Severity: normal
Tags: security

Hi,

The following vulnerability was published for golang-github-disintegration-imaging.

CVE-2023-36308[0]:
| disintegration Imaging 1.6.2 allows attackers to cause a panic
| (because of an integer index out of range during a Grayscale call)
| via a crafted TIFF file to the scan function of scanner.go. NOTE: it
| is unclear whether there are common use cases in which this panic
| could have any security consequence


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-36308
    https://www.cve.org/CVERecord?id=CVE-2023-36308

Please adjust the affected versions in the BTS as needed.

Kind regards,
Maytham
[signature.asc (application/pgp-signature, inline)]

Added tag(s) upstream. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Mon, 15 Apr 2024 18:42:06 GMT) (full text, mbox, link).


Set Bug forwarded-to-address to 'https://github.com/disintegration/imaging/issues/165'. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Mon, 15 Apr 2024 18:42:06 GMT) (full text, mbox, link).


Message sent on to Maytham Alsudany <maytha8thedev@gmail.com>:
Bug#1069062. (Mon, 15 Apr 2024 19:15:03 GMT) (full text, mbox, link).


Message #12 received at 1069062-submitter@bugs.debian.org (full text, mbox, reply):

From: Maytham Alsudany <maytha8thedev@gmail.com>
To: 1069062-submitter@bugs.debian.org
Subject: Bug#1069062 marked as pending in golang-github-disintegration-imaging
Date: Mon, 15 Apr 2024 19:11:35 +0000
Control: tag -1 pending

Hello,

Bug #1069062 in golang-github-disintegration-imaging reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/go-team/packages/golang-github-disintegration-imaging/-/commit/24e17d9e3f43e89f533923139ad87de63690ab7d

------------------------------------------------------------------------
Fix vulnerability that allows attackers to cause a panic via a crafted TIFF file to the scan function of scanner.go (CVE-2023-36308)

Closes: #1069062
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1069062



Added tag(s) pending. Request was from Maytham Alsudany <maytha8thedev@gmail.com> to 1069062-submitter@bugs.debian.org. (Mon, 15 Apr 2024 19:15:03 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Tue Apr 16 11:53:56 2024; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.