THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2023-36308

Assigner:mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca)
Reserved:2023-06-21
Published:2023-09-05
Updated:2024-06-10

Description

disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

References

https://github.com/disintegration/imaging/releases/tag/v1.6.2

https://github.com/disintegration/imaging/issues/165

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3GX2SYGRCNFUAGELLDOBIERCSCYSGKFY/ (FEDORA-2024-25b47765c6) vendor-advisory

cve.org CVE-2023-36308

nvd.nist.gov CVE-2023-36308

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-36308