PT-2023-9225 · Libtiff+6 · Libtiff+6

Marian Rehak

·

Published

2023-10-19

·

Updated

2026-03-31

·

CVE-2023-3164

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions LibTIFF versions prior to the fixed version
Description A heap-buffer-overflow vulnerability was found in LibTIFF, specifically in the extractImageSection() function at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file. The vulnerability is related to buffer copying without input size checking, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For LibTIFF versions prior to the fixed version, consider disabling the extractImageSection() function until a patch is available to prevent potential denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2025-7185
ALT-PU-2025-7532
ALT-PU-2025-8255
AZL-31765
AZL-34952
BDU:2024-04889
CVE-2023-3164
ECHO-CC50-4ED5-0244
MGASA-2024-0213
OESA-2024-1663
OPENSUSE-SU-2024_2028-1
SUSE-SU-2024:1892-1
SUSE-SU-2024:2028-1
SUSE-SU-2024:2028-2
SUSE-SU-2024_1892-1
SUSE-SU-2024_2028-1
USN-6827-1

Affected Products

Alt Linux
Debian
Libtiff
Linuxmint
Red Os
Suse
Ubuntu