VDB
Sign up
MEDIUM5.3

GHSA-44p7-9xx4-hf2g

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

Quick fix

GHSA-44p7-9xx4-hf2g — golang.org/x/image: upgrade to the fixed version with the command below.

go get golang.org/x/image@v0.38.0

Details

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/image
Introduced in: 0Fixed in: 0.38.0
Fixgo get golang.org/x/image@v0.38.0

References