Use After Free in SixLabors.ImageSharp
Package
Affected versions
>= 3.0.0, < 3.1.3
< 2.1.7
Patched versions
3.1.3
2.1.7
Description
Published to the GitHub Advisory Database
Mar 5, 2024
Reviewed
Mar 5, 2024
Published by the National Vulnerability Database
Mar 5, 2024
Last updated
Mar 6, 2024
Impact
A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure.
Patches
The problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7.
Workarounds
None
References
None
References