{"id":"CVE-2023-36307","details":"ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField call) via an image of zero width. NOTE: it is unclear whether there are common use cases in which this panic could have any security consequence","aliases":["GHSA-xgmm-3vvr-6c8j"],"modified":"2026-08-12T03:51:26.226049772Z","published":"2023-09-05T00:00:00Z","database_specific":{"cna_assigner":"mitre","isDisputed":true,"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/36xxx/CVE-2023-36307.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/36xxx/CVE-2023-36307.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-36307"},{"type":"FIX","url":"https://github.com/SimonWaldherr/zplgfa/pull/6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/simonwaldherr/zplgfa","events":[{"introduced":"3b69ac96d5e48ac40f61062c4f20719cd53c3084"},{"last_affected":"3b69ac96d5e48ac40f61062c4f20719cd53c3084"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:simonwaldherr:zplgfa:1.1.1:*:*:*:*:go:*:*","extracted_events":[{"introduced":"1.1.1"},{"last_affected":"1.1.1"}]}}],"versions":["1.1.1","v1.1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-36307.json"}}],"schema_version":"1.9.0"}