ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. The problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10.
History

Mon, 24 Mar 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Sixlabors
Sixlabors imagesharp
CPEs cpe:2.3:a:sixlabors:imagesharp:*:*:*:*:*:*:*:*
Vendors & Products Sixlabors
Sixlabors imagesharp

Fri, 07 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Mar 2025 22:30:00 +0000

Type Values Removed Values Added
Description ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. The problem has been patched. All users are advised to upgrade to v3.1.7 or v2.1.10.
Title Out-of-bounds Write in SixLabors ImageSharp
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-07T19:41:43.565Z

Reserved: 2025-03-03T15:10:34.078Z

Link: CVE-2025-27598

cve-icon Vulnrichment

Updated: 2025-03-07T19:41:39.837Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-06T23:15:12.183

Modified: 2025-03-24T18:36:19.670

Link: CVE-2025-27598

cve-icon Redhat

No data.