PT-2023-6962 · Golang+3 · Golang+3

Philippe Antoine

·

Published

2023-08-02

·

Updated

2025-06-20

·

CVE-2023-29408

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Golang (affected versions not specified) TIFF decoder (affected versions not specified)
Description The issue is related to the decoding of large amounts of compressed data, which can consume excessive memory and CPU. A maliciously-crafted image can exploit this to cause a small image to make the decoder decode large amounts of compressed data. This can lead to a denial of service. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For Golang, consider restricting the use of the TIFF decoder until a patch is available. For the TIFF decoder, as a temporary workaround, consider limiting the size of compressed tile data to prevent excessive memory and CPU consumption. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07981
CVE-2023-29408
GHSA-X92R-3VFX-4CV3
GO-2023-1989
OPENSUSE-SU-2024:0194-2
OPENSUSE-SU-2024:13103-1

Affected Products

Debian
Golang
Red Os
Tiff Decoder