6.5
CVSSv3

CVE-2023-29407

Published: 02/08/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

golang image

fedoraproject fedora 37

fedoraproject fedora 38

Vendor Advisories

Debian Bug report logs - #1043159 golang-golang-x-image: CVE-2023-29407 CVE-2023-29408 Package: src:golang-golang-x-image; Maintainer for src:golang-golang-x-image is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 6 Aug 2023 19:27:01 UTC Se ...
DescriptionThe MITRE CVE dictionary describes this issue as: A maliciously-crafted image can cause excessive CPU consumption in decoding A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero ...