PT-2024-22143 · Unknown · Imagesharp

Jimbobsquarepants

·

Published

2024-03-05

·

Updated

2025-01-21

·

CVE-2024-27929

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageSharp versions prior to 2.1.7 ImageSharp versions prior to 3.1.3
Description A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This issue is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure.
Recommendations For versions prior to 2.1.7, upgrade to version 2.1.7 to resolve the issue. For versions prior to 3.1.3, upgrade to version 3.1.3 to resolve the issue. As a temporary workaround, consider avoiding the use of the InitializeImage() function in the PngDecoderCore.cs file until a patch is applied.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2024-27929
GHSA-65X7-C272-7G7R

Affected Products

Imagesharp