Excessive Iteration Affecting golang-golang-x-image package, versions <0.11.0-1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.17% (56th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-GOLANGGOLANGXIMAGE-5821194
  • published5 Aug 2023
  • disclosed2 Aug 2023

Introduced: 2 Aug 2023

CVE-2023-29407  (opens in a new tab)
CWE-834  (opens in a new tab)

How to fix?

Upgrade Debian:unstable golang-golang-x-image to version 0.11.0-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream golang-golang-x-image package and not the golang-golang-x-image package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

CVSS Scores

version 3.1