Description
LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6921, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3333-1 | tiff security update |
Debian DSA |
DSA-5361-1 | tiff security update |
EUVD |
EUVD-2023-12802 | LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6921, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e. |
Ubuntu USN |
USN-5923-1 | LibTIFF vulnerabilities |
References
History
Fri, 21 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-03-21T19:03:22.116Z
Reserved: 2023-02-12T00:00:00.000Z
Link: CVE-2023-0797
Updated: 2024-08-02T05:24:34.516Z
Status : Modified
Published: 2023-02-13T23:15:11.970
Modified: 2025-03-21T19:15:41.577
Link: CVE-2023-0797
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN