ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. This issue has been patched in versions 3.1.3 and 2.1.7.
References
Link | Resource |
---|---|
https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-65x7-c272-7g7r | Exploit Vendor Advisory |
https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-65x7-c272-7g7r | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Jan 2025, 15:14
Type | Values Removed | Values Added |
---|---|---|
First Time |
Sixlabors
Sixlabors imagesharp |
|
CPE | cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:* | |
References | () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-65x7-c272-7g7r - Exploit, Vendor Advisory |
21 Nov 2024, 09:05
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-65x7-c272-7g7r - | |
Summary |
|
06 Mar 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. This issue has been patched in versions 3.1.3 and 2.1.7. |
05 Mar 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-05 17:15
Updated : 2025-01-21 15:14
NVD link : CVE-2024-27929
Mitre link : CVE-2024-27929
CVE.ORG link : CVE-2024-27929
JSON object : View
Products Affected
sixlabors
- imagesharp
CWE
CWE-416
Use After Free