CVE-2024-41132

ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. All users are advised to upgrade to v3.1.5 or v2.1.9.
References
Link Resource
https://docs.sixlabors.com/articles/imagesharp.web/processingcommands.html#securing-processing-commands Product
https://docs.sixlabors.com/articles/imagesharp/security.html Product
https://github.com/SixLabors/ImageSharp/commit/59de13c8cc47f2b402e2c43aa7024511d029d515 Patch
https://github.com/SixLabors/ImageSharp/commit/9816ca45016c5d3859986f3c600e8934bc450a56 Patch
https://github.com/SixLabors/ImageSharp/commit/b496109051cc39feee1f6cde48fca6481de17f9a Patch
https://github.com/SixLabors/ImageSharp/pull/2759 Issue Tracking
https://github.com/SixLabors/ImageSharp/pull/2764 Issue Tracking
https://github.com/SixLabors/ImageSharp/pull/2770 Issue Tracking
https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-qxrv-gp6x-rc23 Vendor Advisory
https://docs.sixlabors.com/articles/imagesharp.web/processingcommands.html#securing-processing-commands Product
https://docs.sixlabors.com/articles/imagesharp/security.html Product
https://github.com/SixLabors/ImageSharp/commit/59de13c8cc47f2b402e2c43aa7024511d029d515 Patch
https://github.com/SixLabors/ImageSharp/commit/9816ca45016c5d3859986f3c600e8934bc450a56 Patch
https://github.com/SixLabors/ImageSharp/commit/b496109051cc39feee1f6cde48fca6481de17f9a Patch
https://github.com/SixLabors/ImageSharp/pull/2759 Issue Tracking
https://github.com/SixLabors/ImageSharp/pull/2764 Issue Tracking
https://github.com/SixLabors/ImageSharp/pull/2770 Issue Tracking
https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-qxrv-gp6x-rc23 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:32

Type Values Removed Values Added
References () https://docs.sixlabors.com/articles/imagesharp.web/processingcommands.html#securing-processing-commands - Product () https://docs.sixlabors.com/articles/imagesharp.web/processingcommands.html#securing-processing-commands - Product
References () https://docs.sixlabors.com/articles/imagesharp/security.html - Product () https://docs.sixlabors.com/articles/imagesharp/security.html - Product
References () https://github.com/SixLabors/ImageSharp/commit/59de13c8cc47f2b402e2c43aa7024511d029d515 - Patch () https://github.com/SixLabors/ImageSharp/commit/59de13c8cc47f2b402e2c43aa7024511d029d515 - Patch
References () https://github.com/SixLabors/ImageSharp/commit/9816ca45016c5d3859986f3c600e8934bc450a56 - Patch () https://github.com/SixLabors/ImageSharp/commit/9816ca45016c5d3859986f3c600e8934bc450a56 - Patch
References () https://github.com/SixLabors/ImageSharp/commit/b496109051cc39feee1f6cde48fca6481de17f9a - Patch () https://github.com/SixLabors/ImageSharp/commit/b496109051cc39feee1f6cde48fca6481de17f9a - Patch
References () https://github.com/SixLabors/ImageSharp/pull/2759 - Issue Tracking () https://github.com/SixLabors/ImageSharp/pull/2759 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/pull/2764 - Issue Tracking () https://github.com/SixLabors/ImageSharp/pull/2764 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/pull/2770 - Issue Tracking () https://github.com/SixLabors/ImageSharp/pull/2770 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-qxrv-gp6x-rc23 - Vendor Advisory () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-qxrv-gp6x-rc23 - Vendor Advisory
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.3

11 Sep 2024, 15:03

Type Values Removed Values Added
References () https://docs.sixlabors.com/articles/imagesharp.web/processingcommands.html#securing-processing-commands - () https://docs.sixlabors.com/articles/imagesharp.web/processingcommands.html#securing-processing-commands - Product
References () https://docs.sixlabors.com/articles/imagesharp/security.html - () https://docs.sixlabors.com/articles/imagesharp/security.html - Product
References () https://github.com/SixLabors/ImageSharp/commit/59de13c8cc47f2b402e2c43aa7024511d029d515 - () https://github.com/SixLabors/ImageSharp/commit/59de13c8cc47f2b402e2c43aa7024511d029d515 - Patch
References () https://github.com/SixLabors/ImageSharp/commit/9816ca45016c5d3859986f3c600e8934bc450a56 - () https://github.com/SixLabors/ImageSharp/commit/9816ca45016c5d3859986f3c600e8934bc450a56 - Patch
References () https://github.com/SixLabors/ImageSharp/commit/b496109051cc39feee1f6cde48fca6481de17f9a - () https://github.com/SixLabors/ImageSharp/commit/b496109051cc39feee1f6cde48fca6481de17f9a - Patch
References () https://github.com/SixLabors/ImageSharp/pull/2759 - () https://github.com/SixLabors/ImageSharp/pull/2759 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/pull/2764 - () https://github.com/SixLabors/ImageSharp/pull/2764 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/pull/2770 - () https://github.com/SixLabors/ImageSharp/pull/2770 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-qxrv-gp6x-rc23 - () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-qxrv-gp6x-rc23 - Vendor Advisory
First Time Sixlabors imagesharp
Sixlabors
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
CWE CWE-770

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) ImageSharp es una API de gráficos 2D. Una vulnerabilidad descubierta en la librería ImageSharp, donde el procesamiento de archivos especialmente manipulados puede provocar un uso excesivo de memoria en el decodificador Gif. La vulnerabilidad se activa cuando ImageSharp intenta procesar archivos de imagen diseñados para explotar este fallo. Se recomienda a todos los usuarios que actualicen a v3.1.5 o v2.1.9.

22 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-22 15:15

Updated : 2024-11-21 09:32


NVD link : CVE-2024-41132

Mitre link : CVE-2024-41132

CVE.ORG link : CVE-2024-41132


JSON object : View

Products Affected

sixlabors

  • imagesharp
CWE
CWE-789

Memory Allocation with Excessive Size Value

CWE-770

Allocation of Resources Without Limits or Throttling