CVE-2024-32036
MEDIUMDescription
ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker passes a specially crafted JPEG or TGA image file to a software using ImageSharp, potentially disclosing sensitive information from other parts of the software in the resulting image buffer. The problem has been patched in v3.1.4 and v2.1.8.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sixlabors | imagesharp |
| sixlabors | imagesharp |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-32036? +
How severe is CVE-2024-32036? +
What products are affected by CVE-2024-32036? +
How do I check if I'm vulnerable to CVE-2024-32036? +
Related Vulnerabilities
Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of …
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be …
SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed …
The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). …
Sensitive information in resource not removed before reuse in some Intel(R) TDX Seamldr module software before version 1.5.02.00 may allow …
wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue …