HIGH7.5
GHSA-63p8-c4ww-9cg7
SixLabors ImageSharp Out-of-bounds Write
Quick fix
GHSA-63p8-c4ww-9cg7 — SixLabors.ImageSharp: upgrade to the fixed version with the command below.
dotnet add package SixLabors.ImageSharp --version 2.1.9Details
### Impact An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service.
### Patches The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9.
### Workarounds None.
### References https://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/SixLabors.ImageSharp
Introduced in:
0Fixed in: 2.1.9Fix
dotnet add package SixLabors.ImageSharp --version 2.1.9NuGet/SixLabors.ImageSharp
Introduced in:
3.0.0Fixed in: 3.1.5Fix
dotnet add package SixLabors.ImageSharp --version 3.1.5References
- https://github.com/SixLabors/ImageSharp/security/advisories/GHSA-63p8-c4ww-9cg7[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-41131[ADVISORY]
- https://github.com/SixLabors/ImageSharp/pull/2754[WEB]
- https://github.com/SixLabors/ImageSharp/pull/2756[WEB]
- https://github.com/SixLabors/ImageSharp/commit/9dda64a8186af67baf06b6d9c1ab599c3608b693[WEB]
- https://github.com/SixLabors/ImageSharp/commit/a1f287977139109a987065643b8172c748abdadb[WEB]
- https://github.com/SixLabors/ImageSharp[PACKAGE]