PT-2023-6790 · Libtiff+7 · Libtiff+7

Yair Mizrahi

·

Published

2023-01-24

·

Updated

2025-06-26

·

CVE-2023-3316

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions LibTIFF (affected versions not specified)
Description A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file, such as a non-existent path or a path that requires permissions like /dev/null, while specifying zones. This issue may allow a remote attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:6575
ALT-PU-2025-7185
ALT-PU-2025-7532
ALT-PU-2025-8255
AZL-27205
AZL-43885
AZL-44130
BDU:2023-07651
CVE-2023-3316
DLA-3513-1
DLA-4026-1
MGASA-2023-0255
OESA-2023-1385
OPENSUSE-SU-2023_4370-1
RHSA-2023:6575
RHSA-2023_6575
ROSA-SA-2025-2627
SUSE-SU-2023:4370-1
SUSE-SU-2023:4371-1
USN-6229-1
USN-6290-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Libtiff
Linuxmint
Red Hat
Suse
Ubuntu