Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server unresponsive for an extended period of time by linking to specially crafted image file.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44263 Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server unresponsive for an extended period of time by linking to specially crafted image file.
Fixes

Solution

Update Mattermost to versions v7.8.7, v7.9.5, v7.10.3 or higher.


Workaround

No workaround given by the vendor.

References
History

Mon, 21 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-10-21T19:39:59.068Z

Reserved: 2023-07-11T09:04:11.707Z

Link: CVE-2023-3614

cve-icon Vulnrichment

Updated: 2024-08-02T07:01:57.084Z

cve-icon NVD

Status : Modified

Published: 2023-07-17T16:15:11.173

Modified: 2024-11-21T08:17:40.407

Link: CVE-2023-3614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.