6.5
CVSSv3

CVE-2023-29408

Published: 02/08/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height, and encoded size) to make the decoder decode large amounts of compressed data, consuming excessive memory and CPU.

Vulnerable Product Search on Vulmon Subscribe to Product

golang image

fedoraproject fedora 37

fedoraproject fedora 38

Vendor Advisories

Debian Bug report logs - #1043159 golang-golang-x-image: CVE-2023-29407 CVE-2023-29408 Package: src:golang-golang-x-image; Maintainer for src:golang-golang-x-image is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 6 Aug 2023 19:27:01 UTC Se ...
DescriptionThe MITRE CVE dictionary describes this issue as: The TIFF decoder does not place a limit on the size of compressed tile data A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height, and encoded size) to make the decoder decode large amounts of compressed data, consuming excessive memory ...