NA

CVE-2023-0797

Published: 13/02/2023 Updated: 30/05/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6921, allowing malicious users to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff

Vendor Advisories

Synopsis Moderate: libtiff security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for libtiff is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a se ...
Debian Bug report logs - #1031632 tiff: CVE-2023-0795 CVE-2023-0796 CVE-2023-0797 CVE-2023-0798 CVE-2023-0799 CVE-2023-0800 CVE-2023-0801 CVE-2023-0802 CVE-2023-0803 CVE-2023-0804 Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg&gt ...
Several flaws were found in tiffcrop, a program distributed by tiff, the Tag Image File Format (TIFF) library and tools A specially crafted tiff file can lead to an out-of-bounds write or read resulting in a denial of service For the stable distribution (bullseye), this problem has been fixed in version 420-1+deb11u4 We recommend that you upgr ...
LibTIFF 440 has an out-of-bounds read in tiffcrop in tools/tiffcropc:3488, allowing attackers to cause a denial-of-service via a crafted tiff file For users that compile libtiff from sources, the fix is available with commit afaabc3e (CVE-2023-0795) LibTIFF 440 has an out-of-bounds read in tiffcrop in tools/tiffcropc:3592, allowing attacker ...
LibTIFF 440 has an out-of-bounds read in tiffcrop in tools/tiffcropc:3488, allowing attackers to cause a denial-of-service via a crafted tiff file For users that compile libtiff from sources, the fix is available with commit afaabc3e (CVE-2023-0795) LibTIFF 440 has an out-of-bounds read in tiffcrop in tools/tiffcropc:3592, allowing attacker ...
Description<!---->A flaw was found in tiffcrop, a program distributed by the libtiff package A specially crafted tiff file can lead to an out-of-bounds read in the _TIFFmemcpy function in libtiff/tif_unixc when called by functions in tools/tiffcropc, resulting in a Denial of Service and limited information disclosureA flaw was found in tiffcrop ...