You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
** DISPUTED ** disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/disintegration/imaging
vulnerable_at: 1.6.2
packages:
- package: n/a
description: |-
** DISPUTED ** disintegration Imaging 1.6.2 allows attackers to cause a panic
(because of an integer index out of range during a Grayscale call) via a crafted
TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there
are common use cases in which this panic could have any security consequence
cves:
- CVE-2023-36308
references:
- web: https://github.com/disintegration/imaging/releases/tag/v1.6.2
- report: https://github.com/disintegration/imaging/issues/165
The text was updated successfully, but these errors were encountered:
CVE-2023-36308 references github.com/disintegration/imaging, which may be a Go module.
Description:
** DISPUTED ** disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence
References:
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: