/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-qm2h-pg82-q2qw

Published

Last updated

https://images.chainguard.dev/security/CGA-qm2h-pg82-q2qw
Package

mattermost-9.11

Repository

Chainguard

Latest Update
Fixed
Fixed Version

9.11.9-r0

Aliases
  • CVE-2023-36308
  • GHSA-q7pp-wcgr-pffx

Severity

Unknown

Summary

Crash when processing crafted TIFF files

Description

Disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs