Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-36308. PoCs published by vtemlabs.
AI-analyzed exploit summary This repository contains functional exploit code demonstrating CVE-2023-36308, which involves a vulnerability in the imaging library's scanner functionality. The provided test cases and scanner implementation show how the vulnerability can be triggered through image processing operations.
Description
disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of scanner.go. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence
Exploits (1)
This repository contains functional exploit code demonstrating CVE-2023-36308, which involves a vulnerability in the imaging library's scanner functionality. The provided test cases and scanner implementation show how the vulnerability can be triggered through image processing operations.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H