PT-2023-4909 · Libtiff+8 · Libtiff+8

Wangdw.Augustus@Gmail.Com

·

Published

2023-02-07

·

Updated

2025-06-26

·

CVE-2023-0799

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions LibTIFF version 4.4.0
Description The issue is related to an out-of-bounds read in the tiffcrop utility, located in tools/tiffcrop.c:3701, which can be exploited by attackers to cause a denial-of-service via a crafted tiff file. This is also related to the use of memory after it has been freed.
Recommendations For LibTIFF version 4.4.0, the fix is available with commit afaabc3e for users that compile libtiff from sources.

Exploit

Fix

DoS

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2023:3711
ALT-PU-2025-7185
ALT-PU-2025-7532
ALT-PU-2025-8255
AZL-13394
BDU:2023-00654
BDU:2023-05402
CVE-2023-0799
DLA-3333-1
DSA-5361-1
MGASA-2023-0080
OESA-2023-1128
OPENSUSE-SU-2024:12730-1
RHSA-2023:3711
RHSA-2023_3711
RLSA-2023:3711
ROSA-SA-2025-2627
SUSE-SU-2023:2321-1
SUSE-SU-2023:2334-1
USN-5923-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Libtiff
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu