We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-29407

Excessive CPU consumption when decoding 0-height images in golang.org/x/image/tiff



Description

A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

Reserved 2023-04-05 | Published 2023-08-02 | Updated 2024-10-17 | Assigner Go

Problem types

CWE-834: Excessive Iteration

Product status

Default status
unaffected

Any version before 0.10.0
affected

Credits

Philippe Antoine (Catena cyber)

References

go.dev/issue/61581

go.dev/cl/514897

pkg.go.dev/vuln/GO-2023-1990

security.netapp.com/advisory/ntap-20230831-0009/

lists.fedoraproject.org/...KO54NBDUJXKAZNGCFOEYL2LKK2RQP6K6/

lists.fedoraproject.org/...XWH6Q7NVM4MV3GWFEU4PA67AWZHVFJQ2/

lists.fedoraproject.org/...XZTEP6JYILRBNDTNWTEQ5D4QUUVQBESK/

cve.org (CVE-2023-29407)

nvd.nist.gov (CVE-2023-29407)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-29407

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.