Crash when processing crafted TIFF files
Low severity
GitHub Reviewed
Published
Sep 5, 2023
to the GitHub Advisory Database
•
Updated Mar 21, 2024
Description
Published by the National Vulnerability Database
Sep 5, 2023
Published to the GitHub Advisory Database
Sep 5, 2023
Reviewed
Mar 21, 2024
Last updated
Mar 21, 2024
Disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence
References