CVE-2023-3316NULL Pointer Dereference in Libtiff

Severity
6.5MEDIUMNVD
CNA5.9OSV5.5
EPSS
0.0%
top 93.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 19
Latest updateOct 5

Description

A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5libtiff/libtiff3.9.04.5.1
NVDlibtiff/libtiff3.9.04.5.1

Patches

🔴Vulnerability Details

5
OSV
tiff vulnerabilities2023-08-15
OSV
tiff vulnerabilities2023-07-13
OSV
CVE-2023-3316: A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /d2023-06-19
GHSA
GHSA-7mcc-hw35-pqwf: A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /d2023-06-19
CVEList
A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones.2023-06-19

📋Vendor Advisories

6
CISA ICS
Siemens SCALANCE XCM-/XRM-3002024-02-15
Ubuntu
LibTIFF vulnerabilities2023-08-15
Ubuntu
LibTIFF vulnerabilities2023-07-13
Red Hat
libtiff: tiffcrop: null pointer dereference in TIFFClose()2023-06-19
Microsoft
A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones.2023-06-13

📄Research Papers

1
arXiv
Real-VulLLM: An LLM Based Assessment Framework in the Wild2025-10-05