NA

CVE-2023-2731

Published: 17/05/2023 Updated: 03/07/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local malicious user to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff

redhat enterprise linux 9.0

fedoraproject fedora 38

Vendor Advisories

Debian Bug report logs - #1036282 tiff: CVE-2023-2731 Package: src:tiff; Maintainer for src:tiff is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 18 May 2023 13:24:04 UTC Severity: important Tags: security, upstream Found in version tiff/450-5 Fixed in versi ...
Synopsis Low: Logging Subsystem 581- Red Hat OpenShift security update Type/Severity Security Advisory: Low Topic An update is now available for RHOL-58-RHEL-9Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, i ...
Synopsis Moderate: libtiff security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for libtiff is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a se ...
Description<!---->A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzwc file This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of serviceA NULL pointer d ...