CVE-2024-27929
Use After Free in SixLabors.ImageSharp
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. This issue has been patched in versions 3.1.3 and 2.1.7.
ImageSharp es una librería de gráficos 2D multiplataforma administrada. Se encontró una falla de heap-use-after-free en la función InitializeImage() de ImageSharp del archivo PngDecoderCore.cs. Esta vulnerabilidad se activa cuando un atacante pasa un archivo de imagen PNG especialmente manipulado a ImageSharp para su conversión, lo que podría provocar la divulgación de información. Este problema se solucionó en las versiones 3.1.3 y 2.1.7.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-02-28 CVE Reserved
- 2024-03-05 CVE Published
- 2024-03-06 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-65x7-c272-7g7r | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
SixLabors Search vendor "SixLabors" | ImageSharp Search vendor "SixLabors" for product "ImageSharp" | >= 3.0.0 < 3.1.3 Search vendor "SixLabors" for product "ImageSharp" and version " >= 3.0.0 < 3.1.3" | en |
Affected
| ||||||
SixLabors Search vendor "SixLabors" | ImageSharp Search vendor "SixLabors" for product "ImageSharp" | < 2.1.7 Search vendor "SixLabors" for product "ImageSharp" and version " < 2.1.7" | en |
Affected
|