Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-63p8-c4ww-9cg7

Опубликовано: 22 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

SixLabors ImageSharp Out-of-bounds Write

Impact

An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service.

Patches

The problem has been patched. All users are advised to upgrade to v3.1.5 or v2.1.9.

Workarounds

None.

References

https://github.com/SixLabors/ImageSharp/pull/2754 https://github.com/SixLabors/ImageSharp/pull/2756

Пакеты

Наименование

SixLabors.ImageSharp

nuget
Затронутые версииВерсия исправления

< 2.1.9

2.1.9

Наименование

SixLabors.ImageSharp

nuget
Затронутые версииВерсия исправления

>= 3.0.0, < 3.1.5

3.1.5

EPSS

Процентиль: 66%
0.00523
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. All users are advised to upgrade to v3.1.5 or v2.1.9.

EPSS

Процентиль: 66%
0.00523
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-787