MEDIUM
GHSA-q7rw-w4cq-2j6w
bep/imagemeta allows excessively large EXIF data structures
Quick fix
GHSA-q7rw-w4cq-2j6w — github.com/bep/imagemeta: upgrade to the fixed version with the command below.
go get github.com/bep/imagemeta@v0.10.0Details
### Impact The EXIF data format allows for defining excessively large data structures in relatively small payloads. Before `v0.10.0`, If you didn't trust the input images, this could be abused to construct denial-of-service attacks.
### Patches `v0.10.0` added LimitNumTags (default 5000) and LimitTagSize (default 10000) options.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/bep/imagemeta
Introduced in:
0Fixed in: 0.10.0Fix
go get github.com/bep/imagemeta@v0.10.0