Description
A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image.
Remediation
References
https://hackerone.com/reports/315037
Related Vulnerabilities
CVE-2023-41592 Vulnerability in npm package froala-editor
CVE-2020-6858 Vulnerability in maven package com.hotels.styx:styx-api
CVE-2023-27848 Vulnerability in npm package broccoli-compass
CVE-2014-3625 Vulnerability in maven package org.springframework:spring-webmvc
CVE-2020-2205 Vulnerability in maven package org.jenkins-ci.plugins:vncrecorder