PT-2023-3451 · Libtiff+6 · Libtiff+6

Han Zheng

+1

·

Published

2023-04-17

·

Updated

2025-06-26

·

CVE-2023-30774

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libtiff (affected versions not specified)
Description The issue is related to a heap buffer overflow in the libtiff library when processing the TIFFTAG INKNAMES and TIFFTAG NUMBEROFINKS parameters. This can lead to a denial of service or potentially allow an attacker to execute arbitrary code, causing unexpected application termination.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2340
ALT-PU-2025-7185
ALT-PU-2025-7532
ALT-PU-2025-8255
AZL-44023
AZL-44907
BDU:2023-03634
CVE-2023-30774
RHSA-2023:2340
RHSA-2023_2340
ROSA-SA-2025-2657

Affected Products

Alt Linux
Almalinux
Astra Linux
Apple Macos
Red Hat
Red Os
Libtiff