VDB
Sign up
MEDIUM

GHSA-fmhh-rw3h-785m

bep/imagemeta allows a potentially large memory allocation in PNG and WebP parsing

Quick fix

GHSA-fmhh-rw3h-785m — github.com/bep/imagemeta: upgrade to the fixed version with the command below.

go get github.com/bep/imagemeta@v0.11.0

Details

### Impact

The buffer created for parsing metadata for PNG and WebP images was only bounded by their input data type, which could lead to potentially large memory allocation, and unreasonably high for image metadata. Before `v0.11.0`, If you didn't trust the input images, this could be abused to construct denial-of-service attacks.

### Patches

`v0.11.0` added a 10 MB upper limit.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/bep/imagemeta
Introduced in: 0Fixed in: 0.11.0
Fixgo get github.com/bep/imagemeta@v0.11.0

References