Medium severity5.5NVD Advisory· Published Sep 5, 2023· Updated Jun 17, 2026
CVE-2023-36307
CVE-2023-36307
Description
ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField call) via an image of zero width. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
simonwaldherr.de/go/zplgfaGo | <= 1.1.1 | — |
Affected products
3- cpe:2.3:a:simonwaldherr:zplgfa:1.1.1:*:*:*:*:go:*:*
- ZPLGFA/ZPLGFAdescription
Patches
Vulnerability mechanics
References
4- github.com/SimonWaldherr/zplgfa/pull/6nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-xgmm-3vvr-6c8jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-36307ghsaADVISORY
- github.com/SimonWaldherr/zplgfa/commit/c0d018ffa921cd2460b80f766b7969fbe63678fcghsaWEB
News mentions
0No linked articles in our index yet.