Repository navigation
[GHSA-v76p-62qx-wwq2] ImageSharp: Tiled fax TIFF: tile buffer sized by TileWidth but fax decompressor writes scanlines of ImageWidth — heap OOB write - #10273
Conversation
|
Hi there @JimBobSquarePants! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
🟢 Approval recommended
The advisory is valid JSON and its metadata matches the published releases and backported fix.
0 open findings
What changed in this PR
Updates the ImageSharp advisory to reflect the v3 backport and correct NuGet metadata.
Changes:
- Adds 3.2.0 and 4.1.1 patched-version guidance.
- Splits affected ranges across v3 and v4.
- Corrects the package name to
SixLabors.ImageSharp.
| File | Description |
|---|---|
GHSA-v76p-62qx-wwq2.json |
Updates package identity, affected ranges, and remediation details. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Updates
Comments
The fix has been backported and released in ImageSharp 3.2.0. Split the affected ranges to exclude the fixed v3 release while preserving the existing v4 fix. The repository advisory has already been updated. Correct the NuGet package name to SixLabors.ImageSharp.
Release: https://github.com/SixLabors/ImageSharp/releases/tag/v3.2.0
Repository advisory: GHSA-v76p-62qx-wwq2