MEDIUM5.3
GHSA-5x7m-6737-26cr
SixLabors.ImageSharp vulnerable to data leakage
Quick fix
GHSA-5x7m-6737-26cr — SixLabors.ImageSharp: upgrade to the fixed version with the command below.
dotnet add package SixLabors.ImageSharp --version 2.1.8Details
### Impact A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer.
### Patches The problem has been patched. All users are advised to upgrade to v3.1.4 or v2.1.8.
### Workarounds None
### References None
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/SixLabors.ImageSharp
Introduced in:
0Fixed in: 2.1.8Fix
dotnet add package SixLabors.ImageSharp --version 2.1.8NuGet/SixLabors.ImageSharp
Introduced in:
3.0.0Fixed in: 3.1.4Fix
dotnet add package SixLabors.ImageSharp --version 3.1.4References
- https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-5x7m-6737-26cr[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-32036[ADVISORY]
- https://github.com/SixLabors/ImageSharp/commit/8f0b4d3e680e78d479a88e7b1472bccd8f096d68[WEB]
- https://github.com/SixLabors/ImageSharp/commit/da5f09a42513489fe359578d81cec2f15ba588ba[WEB]
- https://github.com/SixLabors/ImageSharp[PACKAGE]