CVE-2024-32036

ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. The problem has been patched in v3.1.4 and v2.1.8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*

History

09 Jan 2025, 18:14

Type Values Removed Values Added
CPE cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-212
References () https://github.com/SixLabors/ImageSharp/commit/8f0b4d3e680e78d479a88e7b1472bccd8f096d68 - () https://github.com/SixLabors/ImageSharp/commit/8f0b4d3e680e78d479a88e7b1472bccd8f096d68 - Patch
References () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-5x7m-6737-26cr - () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-5x7m-6737-26cr - Vendor Advisory
References () https://github.com/SixLabors/ImageSharp/commit/da5f09a42513489fe359578d81cec2f15ba588ba - () https://github.com/SixLabors/ImageSharp/commit/da5f09a42513489fe359578d81cec2f15ba588ba - Patch
First Time Sixlabors imagesharp
Sixlabors

16 Apr 2024, 23:15

Type Values Removed Values Added
Summary ImageSharp is a 2D graphics API. A heap-use-after-free flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to ImageSharp for conversion, potentially leading to information disclosure. The problem has been patched in v3.1.4 and v2.1.8. ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. The problem has been patched in v3.1.4 and v2.1.8.

16 Apr 2024, 13:24

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-15 20:15

Updated : 2025-01-09 18:14


NVD link : CVE-2024-32036

Mitre link : CVE-2024-32036


JSON object : View

Products Affected

sixlabors

  • imagesharp
CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer