CVE-2024-41132

ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. All users are advised to upgrade to v3.1.5 or v2.1.9.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*

History

11 Sep 2024, 15:03

Type Values Removed Values Added
CWE CWE-770
CPE cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 7.5
First Time Sixlabors imagesharp
Sixlabors
References () https://docs.sixlabors.com/articles/imagesharp.web/processingcommands.html#securing-processing-commands - () https://docs.sixlabors.com/articles/imagesharp.web/processingcommands.html#securing-processing-commands - Product
References () https://docs.sixlabors.com/articles/imagesharp/security.html - () https://docs.sixlabors.com/articles/imagesharp/security.html - Product
References () https://github.com/SixLabors/ImageSharp/commit/59de13c8cc47f2b402e2c43aa7024511d029d515 - () https://github.com/SixLabors/ImageSharp/commit/59de13c8cc47f2b402e2c43aa7024511d029d515 - Patch
References () https://github.com/SixLabors/ImageSharp/commit/9816ca45016c5d3859986f3c600e8934bc450a56 - () https://github.com/SixLabors/ImageSharp/commit/9816ca45016c5d3859986f3c600e8934bc450a56 - Patch
References () https://github.com/SixLabors/ImageSharp/commit/b496109051cc39feee1f6cde48fca6481de17f9a - () https://github.com/SixLabors/ImageSharp/commit/b496109051cc39feee1f6cde48fca6481de17f9a - Patch
References () https://github.com/SixLabors/ImageSharp/pull/2759 - () https://github.com/SixLabors/ImageSharp/pull/2759 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/pull/2764 - () https://github.com/SixLabors/ImageSharp/pull/2764 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/pull/2770 - () https://github.com/SixLabors/ImageSharp/pull/2770 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-qxrv-gp6x-rc23 - () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-qxrv-gp6x-rc23 - Vendor Advisory

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) ImageSharp es una API de gráficos 2D. Una vulnerabilidad descubierta en la librería ImageSharp, donde el procesamiento de archivos especialmente manipulados puede provocar un uso excesivo de memoria en el decodificador Gif. La vulnerabilidad se activa cuando ImageSharp intenta procesar archivos de imagen diseñados para explotar este fallo. Se recomienda a todos los usuarios que actualicen a v3.1.5 o v2.1.9.

22 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-22 15:15

Updated : 2024-09-11 15:03


NVD link : CVE-2024-41132

Mitre link : CVE-2024-41132

CVE.ORG link : CVE-2024-41132


JSON object : View

Products Affected

sixlabors

  • imagesharp
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-789

Memory Allocation with Excessive Size Value