6.5
CVSSv3

CVE-2023-41175

Published: 05/10/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote malicious users to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

libtiff libtiff

fedoraproject fedora -

redhat enterprise linux 8.0

redhat enterprise linux 9.0

Vendor Advisories

Multiple buffer overflows and memory leak issues have been found in tiff, the Tag Image File Format (TIFF) library and tools, which may cause denial of service when processing a crafted TIFF image For the oldstable distribution (bullseye), these problems have been fixed in version 420-1+deb11u5 For the stable distribution (bookworm), these prob ...
Multiple potential integer overflow in raw2tiffc in libtiff <= 451 can allow remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image which triggers a heap-based buffer overflow (CVE-2023-41175) ...