Hide Forgot
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service. https://go.dev/cl/468195 https://go.dev/issue/58003 https://groups.google.com/g/golang-announce/c/ag-FiyjlD5o https://pkg.go.dev/vuln/GO-2023-1572
Created golang-x-image tracking bugs for this issue: Affects: fedora-all [bug 2178355] Created hugo tracking bugs for this issue: Affects: fedora-all [bug 2178354]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-41727