DirectorySecurity Advisories
Sign In
Security Advisories

CGA-rjh8-378v-6q7c

Published

Last updated

https://images.chainguard.dev/security/CGA-rjh8-378v-6q7c
Package

mattermost-10.2

Latest Update
Pending upstream fix
Aliases
  • CVE-2023-36308
  • GHSA-q7pp-wcgr-pffx

Summary

Crash when processing crafted TIFF files

Description

Disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images