First published: Wed Aug 02 2023(Updated: )
A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.
Credit: security@golang.org security@golang.org security@golang.org
Affected Software | Affected Version | How to fix |
---|---|---|
Golang Image | <0.10.0 | |
go/golang.org/x/image | <0.10.0 | 0.10.0 |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29407 is a vulnerability that allows a maliciously-crafted image to cause excessive CPU consumption in decoding.
CVE-2023-29407 works by using a tiled image with a height of 0 and a very large width to cause excessive CPU consumption.
The severity of CVE-2023-29407 is medium with a severity value of 6.5.
The Golang Image library up to version 0.10.0 is affected by CVE-2023-29407.
To fix CVE-2023-29407, update the Golang Image library to a version beyond 0.10.0.