7.5

CVE-2024-41131

Out-of-bounds Write in SixLabors ImageSharp

ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. All users are advised to upgrade to v3.1.5 or v2.1.9.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SixlaborsImagesharp Version >= 2.1.0 < 2.1.9
SixlaborsImagesharp Version >= 3.1.0 < 3.1.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.471
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://github.com/SixLabors/ImageSharp/commit/9dda64a8186af67baf06b6d9c1ab599c3608b693
Patch
https://github.com/SixLabors/ImageSharp/commit/a1f287977139109a987065643b8172c748abdadb
Patch
https://github.com/SixLabors/ImageSharp/pull/2754
Issue Tracking
https://github.com/SixLabors/ImageSharp/pull/2756
Issue Tracking
https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-63p8-c4ww-9cg7
Vendor Advisory