5.5
CVSSv3

CVE-2023-3164

Published: 02/11/2023 Updated: 08/03/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows malicious users to cause a denial of service via a crafted tiff file.

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff

redhat enterprise linux 7.0

redhat enterprise linux 8.0

redhat enterprise linux 9.0

Vendor Advisories

There exists one heap buffer overflow in _TIFFmemcpy in tif_unixc in libtiff 4010, which allows an attacker to cause a denial-of-service through a crafted tiff file (CVE-2020-18768) A heap buffer overflow in ExtractImageSection function in tiffcropc in libtiff library Version 430 allows attacker to trigger unsafe or out of bounds memory acce ...