Skip to content

x/vulndb: potential Go vuln in github.com/SimonWaldherr/zplgfa: CVE-2023-36307 #2040

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Closed
GoVulnBot opened this issue Sep 5, 2023 · 1 comment
Assignees
Labels
excluded: NOT_A_VULNERABILITY This is not a vulnerability.

Comments

@GoVulnBot
Copy link

CVE-2023-36307 references github.com/SimonWaldherr/zplgfa, which may be a Go module.

Description:
** DISPUTED ** ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField call) via an image of zero width. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence

References:

Cross references:
No existing reports found with this module or alias.

See doc/triage.md for instructions on how to triage this report.

modules:
    - module: github.com/SimonWaldherr/zplgfa
      vulnerable_at: 1.1.1
      packages:
        - package: n/a
description: |-
    ** DISPUTED ** ZPLGFA 1.1.1 allows attackers to cause a panic (because of an
    integer index out of range during a ConvertToGraphicField call) via an image of
    zero width. NOTE: it is unclear whether there are common use cases in which this
    panic could have any security consequence
cves:
    - CVE-2023-36307
references:
    - fix: https://github.com/SimonWaldherr/zplgfa/pull/6

@timothy-king timothy-king self-assigned this Sep 8, 2023
@timothy-king timothy-king added the excluded: NOT_A_VULNERABILITY This is not a vulnerability. label Sep 8, 2023
@gopherbot
Copy link
Contributor

Change https://go.dev/cl/527176 mentions this issue: data/excluded: batch add 14 excluded reports

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
excluded: NOT_A_VULNERABILITY This is not a vulnerability.
Projects
None yet
Development

No branches or pull requests

3 participants