CVE-2024-41132 Information
Description
ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. All users are advised to upgrade to v3.1.5 or v2.1.9.
Reference
https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-qxrv-gp6x-rc23 https://github.com/SixLabors/ImageSharp/pull/2759 https://github.com/SixLabors/ImageSharp/pull/2764 https://github.com/SixLabors/ImageSharp/pull/2770 https://github.com/SixLabors/ImageSharp/commit/59de13c8cc47f2b402e2c43aa7024511d029d515 https://github.com/SixLabors/ImageSharp/commit/9816ca45016c5d3859986f3c600e8934bc450a56 https://github.com/SixLabors/ImageSharp/commit/b496109051cc39feee1f6cde48fca6481de17f9a https://docs.sixlabors.com/articles/imagesharp.web/processingcommands.html#securing-processing-commands https://docs.sixlabors.com/articles/imagesharp/security.html
Share on: