CVE-2022-41727

CVSS V2 None CVSS V3 None
Description
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
Overview
  • CVE ID
  • CVE-2022-41727
  • Assigner
  • security@golang.org
  • Vulnerability Status
  • Undergoing Analysis
  • Published Version
  • 2023-02-28T18:15:10
  • Last Modified Date
  • 2023-03-10T00:15:40
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:golang:image:*:*:*:*:*:*:*:* 1 OR 0.5.0
cpe:2.3:a:golang:tiff:-:*:*:*:*:*:*:* 1 OR
References
Reference URL Reference Tags
https://go.dev/cl/468195 Patch
https://go.dev/issue/58003 Issue Tracking
https://groups.google.com/g/golang-announce/c/ag-FiyjlD5o Mailing List Vendor Advisory
https://pkg.go.dev/vuln/GO-2023-1572 Vendor Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 05:41:17 Added to TrackCVE
2023-04-17 05:41:20 Weakness Enumeration new