CVE-2024-32036
MEDIUMDescription
ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. The problem has been patched in v3.1.4 and v2.1.8.
Is your site exposed to CVE-2024-32036?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sixlabors | imagesharp |
| sixlabors | imagesharp |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-32036? +
How severe is CVE-2024-32036? +
What products are affected by CVE-2024-32036? +
How do I check if I'm vulnerable to CVE-2024-32036? +
Related Vulnerabilities
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System …
Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of …
Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive …
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be …
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain …
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions …