CVE-2023-29407: Excessive CPU consumption when decoding 0-height images in golang.org/x/image/tiff
Published Aug 2, 2023
·Updated
A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width height) appearing to be zero.
Affected Software
4 affected componentsFixes available
go/golang.org/x/image<0.10.0
0.10.0
Golang Image Go<0.10.0
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Remediation
Patch Available
Patch Available
Event History
Aug 2, 2023
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
DescriptionWeakness
Data Sourced
08:15 PM
Description
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is CVE-2023-29407?
CVE-2023-29407 is a vulnerability that allows a maliciously-crafted image to cause excessive CPU consumption in decoding.
2
How does CVE-2023-29407 work?
CVE-2023-29407 works by using a tiled image with a height of 0 and a very large width to cause excessive CPU consumption.
3
What is the severity of CVE-2023-29407?
The severity of CVE-2023-29407 is medium with a severity value of 6.5.
4
Which software is affected by CVE-2023-29407?
The Golang Image library up to version 0.10.0 is affected by CVE-2023-29407.
5
How can I fix CVE-2023-29407?
To fix CVE-2023-29407, update the Golang Image library to a version beyond 0.10.0.