CVE-2024-27929: Use After Free in SixLabors.ImageSharp
Impact A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure.
Patches The problem has been patched. All users are advised to upgrade to v3.1.3 or v2.1.7.
Workarounds None
References None
Other sources
ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. This issue has been patched in versions 3.1.3 and 2.1.7.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27929?
CVE-2024-27929 is classified as a high severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2024-27929?
To fix CVE-2024-27929, update to version 2.1.7 or 3.1.3 of the SixLabors.ImageSharp package.
What causes the vulnerability CVE-2024-27929?
CVE-2024-27929 is caused by a heap-use-after-free flaw in the InitializeImage() function of the PngDecoderCore.cs file.
In which software is CVE-2024-27929 found?
CVE-2024-27929 affects the SixLabors.ImageSharp package versions below 2.1.7 and between 3.0.0 and 3.1.3.
What happens if CVE-2024-27929 is exploited?
If exploited, CVE-2024-27929 can lead to potential information disclosure when processing specially crafted PNG image files.