PT-2023-5351 · Libtiff+8 · Libtiff+8

Wangdw.Augustus@Gmail.Com

·

Publicado

2023-02-13

·

Atualizado

2025-06-26

·

CVE-2023-0798

CVSS v3.1

6.8

Média

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions LibTIFF version 4.4.0
Description The issue is related to an out-of-bounds read in the tiffcrop function in tools/tiffcrop.c at line 3400, which can be exploited by attackers to cause a denial-of-service via a crafted tiff file. The extractContigSamplesShifted8bits() function is also associated with this buffer read issue, potentially leading to a denial-of-service.
Recommendations For LibTIFF version 4.4.0, users who compile libtiff from sources can apply the fix available with commit afaabc3e.

Exploit

Correção

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2023:3711
ALT-PU-2025-7185
ALT-PU-2025-7532
ALT-PU-2025-8255
AZL-13387
BDU:2023-05979
CVE-2023-0798
DLA-3333-1
DSA-5361-1
MGASA-2023-0080
OESA-2023-1128
OPENSUSE-SU-2024:12730-1
RHSA-2023:3711
RHSA-2023_3711
RLSA-2023:3711
ROSA-SA-2025-2627
SUSE-SU-2023:2321-1
SUSE-SU-2023:2334-1
USN-5923-1

Produtos afetados

Alt Linux
Almalinux
Astra Linux
Libtiff
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu