CVE-2023-3618
published 2023-07-12CVE-2023-3618: A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.19%
64.4th percentile
A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_monterey | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_ventura | — | — |
| debian | debian_linux | — | — |
| debian | tiff | < tiff 4.5.0-6+deb12u2 (bookworm) | tiff 4.5.0-6+deb12u2 (bookworm) |
| libtiff | libtiff | < 4.5.1 | 4.5.1 |
| msrc | azl3_libtiff_4.6.0-6_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libtiff_4.5.1-1_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2023-3618: macOS Sonoma 14.2
vendor_apple·2023-12-11·CVSS 6.5
CVE-2023-3618 [MEDIUM] CVE-2023-3618: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-3618
Component: CVE-2023-3618
Impact: A remote user may be able to cause unexpected app termination or arbitrary code execution
Description: This issue was addressed with improved checks.
Apple
CVE-2023-3618: macOS Monterey 12.7.2
vendor_apple·2023-12-11·CVSS 6.5
CVE-2023-3618 [MEDIUM] CVE-2023-3618: macOS Monterey 12.7.2
Apple Security Update: About the security content of macOS Monterey 12.7.2
Product: macOS Monterey
Version: 12.7.2
CVE: CVE-2023-3618
Component: CVE-2023-3618
Impact: A remote user may be able to cause unexpected app termination or arbitrary code execution
Description: This issue was addressed with improved checks.
Apple
CVE-2023-3618: macOS Ventura 13.6.3
vendor_apple·2023-12-11·CVSS 6.5
CVE-2023-3618 [MEDIUM] CVE-2023-3618: macOS Ventura 13.6.3
Apple Security Update: About the security content of macOS Ventura 13.6.3
Product: macOS Ventura
Version: 13.6.3
CVE: CVE-2023-3618
Component: CVE-2023-3618
Impact: A remote user may be able to cause unexpected app termination or arbitrary code execution
Description: This issue was addressed with improved checks.
Ubuntu
LibTIFF vulnerabilities
vendor_ubuntu·2023-08-15·CVSS 5.5
CVE-2022-48281 [MEDIUM] LibTIFF vulnerabilities
Title: LibTIFF vulnerabilities
Summary: Several security issues were fixed in LibTIFF.
It was discovered that LibTIFF could be made to write out of bounds when
processing certain malformed image files with the tiffcrop utility. If a
user were tricked into opening a specially crafted image file, an attacker
could possibly use this issue to cause tiffcrop to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-48281)
It was discovered that LibTIFF incorrectly handled certain image files. If
a user were tricked into opening a specially crafted image file, an
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 23.04. (CVE-2023-
Microsoft
Segmentation fault in fax3encode in libtiff/tif_fax3.c
vendor_msrc·2023-07-11·CVSS 6.5
CVE-2023-3618 [MEDIUM] CWE-120 Segmentation fault in fax3encode in libtiff/tif_fax3.c
Segmentation fault in fax3encode in libtiff/tif_fax3.c
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://lear
Red Hat
libtiff: segmentation fault in Fax3Encode in libtiff/tif_fax3.c
vendor_redhat·2023-02-13·CVSS 6.5
CVE-2023-3618 [MEDIUM] CWE-120 libtiff: segmentation fault in Fax3Encode in libtiff/tif_fax3.c
libtiff: segmentation fault in Fax3Encode in libtiff/tif_fax3.c
A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.
A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.
Package: libtiff (Red Hat Enterprise Linux 6) - Out of support scope
Package: compat-libtiff3 (Red Hat Enterprise Linux 7) - Out of support scope
Package: libtiff (Red Hat Enterprise Linux 7) - Out of support scope
Package: compat-libtiff3 (Red Hat Enterprise Linux 8) - Will not fix
Package: libtiff (Red Hat Enterprise Linux
Debian
CVE-2023-3618: tiff - A flaw was found in libtiff. A specially crafted tiff file can lead to a segment...
vendor_debian·2023·CVSS 6.5
CVE-2023-3618 [MEDIUM] CVE-2023-3618: tiff - A flaw was found in libtiff. A specially crafted tiff file can lead to a segment...
A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 4.5.0-6+deb12u2)
bullseye: resolved (fixed in 4.2.0-1+deb11u6)
forky: resolved (fixed in 4.5.1~rc3-1)
sid: resolved (fixed in 4.5.1~rc3-1)
trixie: resolved (fixed in 4.5.1~rc3-1)
OSV
tiff vulnerabilities
osv·2023-08-15·CVSS 5.5
CVE-2022-48281 [MEDIUM] tiff vulnerabilities
tiff vulnerabilities
It was discovered that LibTIFF could be made to write out of bounds when
processing certain malformed image files with the tiffcrop utility. If a
user were tricked into opening a specially crafted image file, an attacker
could possibly use this issue to cause tiffcrop to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2022-48281)
It was discovered that LibTIFF incorrectly handled certain image files. If
a user were tricked into opening a specially crafted image file, an
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 23.04. (CVE-2023-2731)
It was discovered that LibTIFF incorrectly handled certain i
GHSA
GHSA-jgp5-27vm-42q7: A flaw was found in libtiff
ghsa_unreviewed·2023-07-12
CVE-2023-3618 [MEDIUM] CWE-120 GHSA-jgp5-27vm-42q7: A flaw was found in libtiff
A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.
OSV
CVE-2023-3618: A flaw was found in libtiff
osv·2023-07-12·CVSS 6.5
CVE-2023-3618 [MEDIUM] CVE-2023-3618: A flaw was found in libtiff
A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-52595 kernel: wifi: rt2x00: restart beacon queue when hardware reset
bugzilla·2024-03-06·CVSS 5.5
CVE-2023-52595 [MEDIUM] CVE-2023-52595 kernel: wifi: rt2x00: restart beacon queue when hardware reset
CVE-2023-52595 kernel: wifi: rt2x00: restart beacon queue when hardware reset
In the Linux kernel, the following vulnerability has been resolved:
wifi: rt2x00: restart beacon queue when hardware reset
The Linux kernel CVE team has assigned CVE-2023-52595 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030645-CVE-2023-52595-d018@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2268316]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-
Bugzilla
CVE-2023-52598 kernel: s390/ptrace: handle setting of fpc register correctly
bugzilla·2024-03-06·CVSS 7.1
CVE-2023-52598 [HIGH] CVE-2023-52598 kernel: s390/ptrace: handle setting of fpc register correctly
CVE-2023-52598 kernel: s390/ptrace: handle setting of fpc register correctly
In the Linux kernel, the following vulnerability has been resolved:
s390/ptrace: handle setting of fpc register correctly
The Linux kernel CVE team has assigned CVE-2023-52598 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030646-CVE-2023-52598-d0a2@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2268310]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52598 is:
Bugzilla
CVE-2023-52594 kernel: wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus()
bugzilla·2024-03-06·CVSS 7.8
CVE-2023-52594 [HIGH] CVE-2023-52594 kernel: wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus()
CVE-2023-52594 kernel: wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus()
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus()
The Linux kernel CVE team has assigned CVE-2023-52594 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030645-CVE-2023-52594-9b84@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2268318]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the foll
Bugzilla
CVE-2023-52606 kernel: powerpc/lib: Validate size for vector operations
bugzilla·2024-03-06·CVSS 5.5
CVE-2023-52606 [MEDIUM] CVE-2023-52606 kernel: powerpc/lib: Validate size for vector operations
CVE-2023-52606 kernel: powerpc/lib: Validate size for vector operations
In the Linux kernel, the following vulnerability has been resolved:
powerpc/lib: Validate size for vector operations
The Linux kernel CVE team has assigned CVE-2023-52606 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030647-CVE-2023-52606-fdcc@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2268294]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52606 is: CHECK May
Bugzilla
CVE-2023-52607 kernel: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add
bugzilla·2024-03-06·CVSS 5.5
CVE-2023-52607 [MEDIUM] CVE-2023-52607 kernel: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add
CVE-2023-52607 kernel: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add
In the Linux kernel, the following vulnerability has been resolved:
powerpc/mm: Fix null-pointer dereference in pgtable_cache_add
The Linux kernel CVE team has assigned CVE-2023-52607 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030647-CVE-2023-52607-75d1@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2268292]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
The result of automatic check (that is developed by Alexander Larkin) for this CV
Bugzilla
CVE-2023-52528 kernel: net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg
bugzilla·2024-03-04·CVSS 5.5
CVE-2023-52528 [MEDIUM] CVE-2023-52528 kernel: net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg
CVE-2023-52528 kernel: net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg
In the Linux kernel, the following vulnerability has been resolved:
net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg
The Linux kernel CVE team has assigned CVE-2023-52528 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030254-CVE-2023-52528-c33b@gregkh/T/#u
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Lar
Bugzilla
CVE-2023-52513 kernel: RDMA/siw: Fix connection failure handling
bugzilla·2024-03-04·CVSS 5.5
CVE-2023-52513 [MEDIUM] CVE-2023-52513 kernel: RDMA/siw: Fix connection failure handling
CVE-2023-52513 kernel: RDMA/siw: Fix connection failure handling
In the Linux kernel, the following vulnerability has been resolved:
RDMA/siw: Fix connection failure handling
The Linux kernel CVE team has assigned CVE-2023-52513 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030251-CVE-2023-52513-5224@gregkh/T/#u
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52513 is: CHECK Maybe valid
Bugzilla
CVE-2023-52520 kernel: platform/x86: think-lmi: Fix reference leak
bugzilla·2024-03-04·CVSS 5.5
CVE-2023-52520 [MEDIUM] CVE-2023-52520 kernel: platform/x86: think-lmi: Fix reference leak
CVE-2023-52520 kernel: platform/x86: think-lmi: Fix reference leak
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: think-lmi: Fix reference leak
The Linux kernel CVE team has assigned CVE-2023-52520 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030252-CVE-2023-52520-0a4e@gregkh/T/#u
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52520 is: CHECK Maybe v
Bugzilla
CVE-2023-52565 kernel: media: uvcvideo: out-of-bounds read in uvc_query_v4l2_menu()
bugzilla·2024-03-04·CVSS 7.1
CVE-2023-52565 [HIGH] CVE-2023-52565 kernel: media: uvcvideo: out-of-bounds read in uvc_query_v4l2_menu()
CVE-2023-52565 kernel: media: uvcvideo: out-of-bounds read in uvc_query_v4l2_menu()
In the Linux kernel, the following vulnerability has been resolved:
media: uvcvideo: Fix OOB read
The Linux kernel CVE team has assigned CVE-2023-52565 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030254-CVE-2023-52565-07ce@gregkh/
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3627 https://access.redhat.com/errata/RHSA-2024:3627
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52565 is: CHECK Maybe va
Bugzilla
CVE-2023-52477 kernel: usb: hub: Guard against accesses to uninitialized BOS descriptors
bugzilla·2024-02-29·CVSS 5.5
CVE-2023-52477 [MEDIUM] CVE-2023-52477 kernel: usb: hub: Guard against accesses to uninitialized BOS descriptors
CVE-2023-52477 kernel: usb: hub: Guard against accesses to uninitialized BOS descriptors
In the Linux kernel, the following vulnerability has been resolved:
usb: hub: Guard against accesses to uninitialized BOS descriptors
The Linux kernel CVE team has assigned CVE-2023-52477 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024022921-CVE-2023-52477-6f20@gregkh/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2267039]
---
This was fixed for Fedora with the 6.5.8 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://access.redhat.com/errata/RHSA-2024:3618
---
This issue has been addressed in the following products:
Red Hat Ente
Bugzilla
CVE-2023-52445 kernel: pvrusb2: fix use after free on context disconnection
bugzilla·2024-02-23·CVSS 7.8
CVE-2023-52445 [HIGH] CVE-2023-52445 kernel: pvrusb2: fix use after free on context disconnection
CVE-2023-52445 kernel: pvrusb2: fix use after free on context disconnection
media: pvrusb2: fix use after free on context disconnection
Upon module load, a kthread is created targeting the
pvr2_context_thread_func function, which may call pvr2_context_destroy
and thus call kfree() on the context object. However, that might happen
before the usb hub_event handler is able to notify the driver. This
patch adds a sanity check before the invalid read reported by syzbot,
within the context disconnection call stack.
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2267102]
---
This was fixed for Fedora with the 6.6.14 stable kernel update.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3618 https://
https://access.redhat.com/security/cve/CVE-2023-3618https://bugzilla.redhat.com/show_bug.cgi?id=2215865https://lists.debian.org/debian-lts-announce/2023/07/msg00034.htmlhttps://security.netapp.com/advisory/ntap-20230824-0012/https://support.apple.com/kb/HT214036https://support.apple.com/kb/HT214037https://support.apple.com/kb/HT214038https://access.redhat.com/security/cve/CVE-2023-3618https://bugzilla.redhat.com/show_bug.cgi?id=2215865https://lists.debian.org/debian-lts-announce/2023/07/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2025/01/msg00019.htmlhttps://security.netapp.com/advisory/ntap-20230824-0012/https://support.apple.com/kb/HT214036https://support.apple.com/kb/HT214037https://support.apple.com/kb/HT214038
2023-07-12
Published