CVE-2024-27929
Sixlabors
CVE-2024-27929: Heap-use-after-free vulnerability in ImageSharp. A specially crafted PNG image can trigger this flaw in the InitializeImage() function of PngDecoderCore.cs. This vulnerability allows for potential information disclosure when converting images using ImageSharp. Patches are available in versions 3.1.3 and 2.1.7 to address this security risk. While the CVSS score is 7.1, the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a lower immediate risk compared to critical vulnerabilities with SVRS scores above 80. Nevertheless, applying the available patches is crucial to prevent exploitation and safeguard sensitive information. The presence of the 'In The Wild' tag suggests potential active exploitation, warranting heightened awareness and prompt remediation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.