ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. The problem has been patched in v3.1.4 and v2.1.8.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Jan 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sixlabors
Sixlabors imagesharp |
|
| Weaknesses | CWE-212 | |
| CPEs | cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sixlabors
Sixlabors imagesharp |
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-04-15T20:08:44.284Z
Updated: 2024-08-02T02:06:42.826Z
Reserved: 2024-04-09T15:29:35.939Z
Link: CVE-2024-32036
Updated: 2024-08-02T02:06:42.826Z
Status : Analyzed
Published: 2024-04-15T20:15:11.543
Modified: 2025-01-09T18:14:46.097
Link: CVE-2024-32036
No data.