PT-2023-4910 · Libtiff+9 · Libtiff+9

4Ugustus

+1

·

Published

2023-02-12

·

Updated

2025-06-26

·

CVE-2023-0800

CVSS v3.1

6.8

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions libtiff version 4.4.0
Description The issue is related to an out-of-bounds write in the tiffcrop utility of the libtiff library, specifically in tools/tiffcrop.c:3502. This can be exploited to cause a denial-of-service via a crafted tiff file.
Recommendations For version 4.4.0, the fix is available with commit 33aee127 for users that compile libtiff from sources.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:3711
ALSA-2023:5353
ALT-PU-2025-7185
ALT-PU-2025-7532
ALT-PU-2025-8255
AZL-13388
BDU:2023-05403
CESA-2023_5353
CVE-2023-0800
DLA-3333-1
DSA-5361-1
MGASA-2023-0080
OESA-2023-1128
OPENSUSE-SU-2024:12730-1
RHSA-2023:3711
RHSA-2023:5353
RHSA-2023_3711
RHSA-2023_5353
RLSA-2023:3711
RLSA-2023:5353
ROSA-SA-2025-2627
SUSE-SU-2023:2321-1
SUSE-SU-2023:2334-1
USN-5923-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Libtiff