Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a small JPEG file to specify dimensions of 64250x64250 pixels, which is mishandled during an attempt to load the 'whole image' into memory.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://obsidianterminal.blogspot.com/2019/07/dos-in-imgix-cdns-image-processing.html | third party advisory |