Impact
The TIFF CCITT Group 4 encoder in ImageSharp allocates a fixed buffer based on image width and rows per strip, but the compressor can emit more data than this buffer holds. As a result, the WriteCode routine performs unchecked writes that may overflow the buffer and corrupt adjacent memory. Attacker-supplied TIFF files that exercise this path can trigger the out-of-bounds writes, potentially causing the process to crash due to memory corruption. The flaw is strictly related to the encoder's buffer management and is classified as an out-of-bounds write
Affected Systems
All deployments of SixLabors ImageSharp from version 2.1.0 up to, but not including, 4.1.2 are vulnerable. Any application that uses ImageSharp to decode or re-encode TIFF images with CCITT Group 4 compression is affected. The vulnerability has been resolved in ImageSharp 4.1.2 and later releases
Risk and Exploitability
The CVSS score of 7.5 places this issue in the medium-to-high severity range, indicating significant impact but not guaranteeing immediate exploitability. EPSS data is currently unavailable, and the vulnerability has not yet been listed in the CISA KEV catalog. Because the flaw is triggered by processing a crafted TIFF file, the attack vector is most likely local or remote via a trusted input channel. An attacker would need to supply a malicious TIFF to an application that processes user data, making the vulnerability exploitable in environments that accept unverified image uploads. Exfiltration cannot occur directly, and the effect is limited to process termination via memory corruption.
OpenCVE Enrichment