SciSharp / NumSharp

High Performance Computation for N-D Tensors in .NET, similar API to NumPy.
https://github.com/SciSharp
Apache License 2.0
1.37k stars 192 forks source link

critical vulnerability in version 5.0.2 of system.drawing.common #492

Open jkl-ds opened 1 year ago

jkl-ds commented 1 year ago

"When a .NET application utilizing libgdiplus on a non-Windows system accepts input, an attacker could send a specially crafted request that could result in remote code execution."

https://github.com/dotnet/announcements/issues/176

Please upgrade to version 5.0.3 or higher.

https://github.com/SciSharp/NumSharp/blob/master/src/NumSharp.Bitmap/NumSharp.Bitmap.csproj#L78