Allocation of Resources Without Limits or Throttling Affecting org.graalvm.sdk:graal-sdk package, versions [,20.3.5) [21.0.0,21.3.1)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
- Snyk ID SNYK-JAVA-ORGGRAALVMSDK-2343493
- published 19 Jan 2022
- disclosed 18 Jan 2022
- credit Unknown
How to fix?
org.graalvm.sdk:graal-sdk to version 20.3.5, 21.3.1 or higher.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling. A flaw was found in the way the
TIFFNullDecompressor class implementation in the
ImageIO component performs reading of uncompressed
TIFF files. A specially-crafted
TIFF image could cause the decompressor to create image objects with an inconsistent state due to failure to fully read the image.