An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
References
Configurations
History
No history.
Information
Published : 2023-02-28 18:15
Updated : 2024-11-21 07:23
NVD link : CVE-2022-41727
Mitre link : CVE-2022-41727
CVE.ORG link : CVE-2022-41727
JSON object : View
Products Affected
golang
- tiff
- image
fedoraproject
- fedora
CWE
CWE-770
Allocation of Resources Without Limits or Throttling