CVE-2024-41132

ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. All users are advised to upgrade to v3.1.5 or v2.1.9.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*

History

11 Sep 2024, 15:03

Type Values Removed Values Added
First Time Sixlabors imagesharp
Sixlabors
CWE CWE-770
References () https://github.com/SixLabors/ImageSharp/commit/59de13c8cc47f2b402e2c43aa7024511d029d515 - () https://github.com/SixLabors/ImageSharp/commit/59de13c8cc47f2b402e2c43aa7024511d029d515 - Patch
References () https://docs.sixlabors.com/articles/imagesharp.web/processingcommands.html#securing-processing-commands - () https://docs.sixlabors.com/articles/imagesharp.web/processingcommands.html#securing-processing-commands - Product
References () https://github.com/SixLabors/ImageSharp/commit/9816ca45016c5d3859986f3c600e8934bc450a56 - () https://github.com/SixLabors/ImageSharp/commit/9816ca45016c5d3859986f3c600e8934bc450a56 - Patch
References () https://github.com/SixLabors/ImageSharp/pull/2770 - () https://github.com/SixLabors/ImageSharp/pull/2770 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/pull/2759 - () https://github.com/SixLabors/ImageSharp/pull/2759 - Issue Tracking
References () https://docs.sixlabors.com/articles/imagesharp/security.html - () https://docs.sixlabors.com/articles/imagesharp/security.html - Product
References () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-qxrv-gp6x-rc23 - () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-qxrv-gp6x-rc23 - Vendor Advisory
References () https://github.com/SixLabors/ImageSharp/pull/2764 - () https://github.com/SixLabors/ImageSharp/pull/2764 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/commit/b496109051cc39feee1f6cde48fca6481de17f9a - () https://github.com/SixLabors/ImageSharp/commit/b496109051cc39feee1f6cde48fca6481de17f9a - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*

22 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-22 15:15

Updated : 2024-09-11 15:03


NVD link : CVE-2024-41132

Mitre link : CVE-2024-41132


JSON object : View

Products Affected

sixlabors

  • imagesharp
CWE
CWE-770

Allocation of Resources Without Limits or Throttling