6.5
CVSSv3

CVE-2023-40745

Published: 05/10/2023 Updated: 21/01/2024
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

LibTIFF is vulnerable to an integer overflow. This flaw allows remote malicious users to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff

fedoraproject fedora -

redhat enterprise linux 8.0

netapp active iq unified manager -

redhat enterprise linux 9.0

Vendor Advisories

Multiple buffer overflows and memory leak issues have been found in tiff, the Tag Image File Format (TIFF) library and tools, which may cause denial of service when processing a crafted TIFF image For the oldstable distribution (bullseye), these problems have been fixed in version 420-1+deb11u5 For the stable distribution (bookworm), these prob ...