5.5
CVSSv3

CVE-2023-36308

Published: 05/09/2023 Updated: 17/05/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

disintegration Imaging 1.6.2 allows malicious users to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

Vulnerable Product Search on Vulmon Subscribe to Product

disintegration imaging 1.6.2

Vendor Advisories

Debian Bug report logs - #1069062 golang-github-disintegration-imaging: CVE-2023-36308 Package: golang-github-disintegration-imaging; Maintainer for golang-github-disintegration-imaging is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Maytham Alsudany <maytha8thedev@gmailcom> Date: Mon, 15 A ...