CVE-2024-41131

ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. All users are advised to upgrade to v3.1.5 or v2.1.9.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*

History

11 Sep 2024, 14:40

Type Values Removed Values Added
First Time Sixlabors
Sixlabors imagesharp
CPE cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
References () https://github.com/SixLabors/ImageSharp/commit/9dda64a8186af67baf06b6d9c1ab599c3608b693 - () https://github.com/SixLabors/ImageSharp/commit/9dda64a8186af67baf06b6d9c1ab599c3608b693 - Patch
References () https://github.com/SixLabors/ImageSharp/commit/a1f287977139109a987065643b8172c748abdadb - () https://github.com/SixLabors/ImageSharp/commit/a1f287977139109a987065643b8172c748abdadb - Patch
References () https://github.com/SixLabors/ImageSharp/pull/2754 - () https://github.com/SixLabors/ImageSharp/pull/2754 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/pull/2756 - () https://github.com/SixLabors/ImageSharp/pull/2756 - Issue Tracking
References () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-63p8-c4ww-9cg7 - () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-63p8-c4ww-9cg7 - Vendor Advisory

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) ImageSharp es una API de gráficos 2D. Se ha encontrado una vulnerabilidad de escritura fuera de los límites en el decodificador de gif de ImageSharp, lo que permite a los atacantes provocar un bloqueo utilizando un gif especialmente manipulado. Esto puede conducir potencialmente a la denegación del servicio. Se recomienda a todos los usuarios que actualicen a v3.1.5 o v2.1.9.

22 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-22 15:15

Updated : 2024-09-11 14:40


NVD link : CVE-2024-41131

Mitre link : CVE-2024-41131

CVE.ORG link : CVE-2024-41131


JSON object : View

Products Affected

sixlabors

  • imagesharp
CWE
CWE-787

Out-of-bounds Write