CVE-2023-1916Out-of-bounds Read in Libtiff

CWE-125Out-of-bounds Read11 documents9 sources
Severity
6.1MEDIUMNVD
EPSS
0.0%
top 96.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 10
Latest updateOct 11

Description

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:HExploitability: 1.8 | Impact: 4.2

Affected Packages2 packages

NVDlibtiff/libtiff4.04.5.0
CVEListV5libtiff/libtifflibtiff versions 4.x and newer are affected

🔴Vulnerability Details

3
GHSA
GHSA-mh23-v522-9fqx: A flaw was found in tiffcrop, a program distributed by the libtiff package2023-04-11
OSV
CVE-2023-1916: A flaw was found in tiffcrop, a program distributed by the libtiff package2023-04-10
CVEList
CVE-2023-1916: A flaw was found in tiffcrop, a program distributed by the libtiff package2023-04-10

📋Vendor Advisories

7
Ubuntu
LibTIFF vulnerability2023-10-11
Apple
CVE-2023-1916: macOS Monterey 12.6.82023-07-24
Apple
CVE-2023-1916: macOS Ventura 13.52023-07-24
Apple
CVE-2023-29491: macOS Monterey 12.6.82023-07-24
Microsoft
A flaw was found in tiffcrop a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c resul2023-04-11