CVE-2024-32036

ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. The problem has been patched in v3.1.4 and v2.1.8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*

History

09 Jan 2025, 18:14

Type Values Removed Values Added
First Time Sixlabors
Sixlabors imagesharp
CPE cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
CWE CWE-212
References () https://github.com/SixLabors/ImageSharp/commit/8f0b4d3e680e78d479a88e7b1472bccd8f096d68 - () https://github.com/SixLabors/ImageSharp/commit/8f0b4d3e680e78d479a88e7b1472bccd8f096d68 - Patch
References () https://github.com/SixLabors/ImageSharp/commit/da5f09a42513489fe359578d81cec2f15ba588ba - () https://github.com/SixLabors/ImageSharp/commit/da5f09a42513489fe359578d81cec2f15ba588ba - Patch
References () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-5x7m-6737-26cr - () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-5x7m-6737-26cr - Vendor Advisory

21 Nov 2024, 09:14

Type Values Removed Values Added
References () https://github.com/SixLabors/ImageSharp/commit/8f0b4d3e680e78d479a88e7b1472bccd8f096d68 - () https://github.com/SixLabors/ImageSharp/commit/8f0b4d3e680e78d479a88e7b1472bccd8f096d68 -
References () https://github.com/SixLabors/ImageSharp/commit/da5f09a42513489fe359578d81cec2f15ba588ba - () https://github.com/SixLabors/ImageSharp/commit/da5f09a42513489fe359578d81cec2f15ba588ba -
References () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-5x7m-6737-26cr - () https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-5x7m-6737-26cr -

16 Apr 2024, 23:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.1
v2 : unknown
v3 : 5.3

16 Apr 2024, 22:15

Type Values Removed Values Added
CWE CWE-416
Summary (en) ImageSharp is a 2D graphics API. A heap-use-after-free flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to ImageSharp for conversion, potentially leading to information disclosure. The problem has been patched in v3.1.4 and v2.1.8. (en) ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. The problem has been patched in v3.1.4 and v2.1.8.

15 Apr 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-15 20:15

Updated : 2025-01-09 18:14


NVD link : CVE-2024-32036

Mitre link : CVE-2024-32036

CVE.ORG link : CVE-2024-32036


JSON object : View

Products Affected

sixlabors

  • imagesharp
CWE
CWE-226

Sensitive Information in Resource Not Removed Before Reuse

CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer