CVE-2024-27929

ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when an attacker passes a specially crafted PNG image file to ImageSharp for conversion, potentially leading to information disclosure. This issue has been patched in versions 3.1.3 and 2.1.7.
Configurations

No configuration.

History

No history.

Information

Published : 2024-03-05 17:15

Updated : 2024-03-06 22:15


NVD link : CVE-2024-27929

Mitre link : CVE-2024-27929

CVE.ORG link : CVE-2024-27929


JSON object : View

Products Affected

No product.

CWE
CWE-416

Use After Free