PT-2023-5349 · Libtiff+8 · Libtiff+8

Wangdw.Augustus@Gmail.Com

·

Published

2023-02-13

·

Updated

2025-06-26

·

CVE-2023-0796

CVSS v3.1

6.8

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions LibTIFF version 4.4.0
Description The issue is related to an out-of-bounds read in the tiffcrop utility of the LibTIFF library, specifically in the tools/tiffcrop.c file at line 3592. This can lead to a denial-of-service when a crafted tiff file is processed.
Recommendations For version 4.4.0, users who compile libtiff from sources can apply the fix available with commit afaabc3e to resolve the issue.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:3711
ALT-PU-2025-7185
ALT-PU-2025-7532
ALT-PU-2025-8255
AZL-13390
BDU:2023-05977
CVE-2023-0796
DLA-3333-1
DSA-5361-1
MGASA-2023-0080
OESA-2023-1128
OPENSUSE-SU-2024:12730-1
RHSA-2023:3711
RHSA-2023_3711
RLSA-2023:3711
ROSA-SA-2025-2627
SUSE-SU-2023:2321-1
SUSE-SU-2023:2334-1
USN-5923-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Libtiff
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu