An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
| Software | From | Fixed in |
|---|---|---|
| golang / image | - | 0.5.0 |
golang.org/x/image
|
- | 0.5.0 |
| fedoraproject / fedora | 37 | 37.x |
| fedoraproject / fedora | 38 | 38.x |