CVE-2024-41132
MEDIUMDescription
ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit this flaw. All users are advised to upgrade to v3.1.5 or v2.1.9.
Is your site exposed to CVE-2024-41132?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sixlabors | imagesharp |
| sixlabors | imagesharp |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-41132? +
How severe is CVE-2024-41132? +
What products are affected by CVE-2024-41132? +
How do I check if I'm vulnerable to CVE-2024-41132? +
Related Vulnerabilities
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects …
In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also …
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also …
A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty …
Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirements on high availability. …