Package: golang-github-disintegration-imaging
X-Debbugs-CC: t...@security.debian.org
Severity: normal
Tags: security

Hi,

The following vulnerability was published for 
golang-github-disintegration-imaging.

CVE-2023-36308[0]:
| disintegration Imaging 1.6.2 allows attackers to cause a panic
| (because of an integer index out of range during a Grayscale call)
| via a crafted TIFF file to the scan function of scanner.go. NOTE: it
| is unclear whether there are common use cases in which this panic
| could have any security consequence


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-36308
    https://www.cve.org/CVERecord?id=CVE-2023-36308

Please adjust the affected versions in the BTS as needed.

Kind regards,
Maytham

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to