Severity
6.5MEDIUMNVD
EPSS
0.3%
top 43.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 5
Latest updateOct 10

Description

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDlibtiff/libtiff< 4.6.0

Also affects: Enterprise Linux 8.0, 9.0

🔴Vulnerability Details

3
OSV
CVE-2023-41175: A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff2023-10-05
CVEList
Libtiff: potential integer overflow in raw2tiff.c2023-10-05
GHSA
GHSA-hjwh-g78g-5xvp: A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff2023-10-05

📋Vendor Advisories

3
Microsoft
Libtiff: potential integer overflow in raw2tiff.c2023-10-10
Red Hat
libtiff: potential integer overflow in raw2tiff.c2023-07-21
Debian
CVE-2023-41175: tiff - A vulnerability was found in libtiff due to multiple potential integer overflows...2023
CVE-2023-41175 — Integer Overflow or Wraparound | cvebase