CVE-2023-41175
published 2023-10-05CVE-2023-41175: A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.03%
60.2th percentile
A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tiff | < tiff 4.5.0-6+deb12u1 (bookworm) | tiff 4.5.0-6+deb12u1 (bookworm) |
| libtiff | libtiff | < 4.6.0 | 4.6.0 |
| msrc | cbl2_libtiff_4.6.0-1_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-41175: A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff
osv·2023-10-05·CVSS 6.5
CVE-2023-41175 [MEDIUM] CVE-2023-41175: A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff
A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.
GHSA
GHSA-hjwh-g78g-5xvp: A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff
ghsa_unreviewed·2023-10-05
CVE-2023-41175 [MEDIUM] CWE-122 GHSA-hjwh-g78g-5xvp: A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff
A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.
Microsoft
Libtiff: potential integer overflow in raw2tiff.c
vendor_msrc·2023-10-10·CVSS 6.5
CVE-2023-41175 [MEDIUM] CWE-190 Libtiff: potential integer overflow in raw2tiff.c
Libtiff: potential integer overflow in raw2tiff.c
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.mic
Red Hat
libtiff: potential integer overflow in raw2tiff.c
vendor_redhat·2023-07-21·CVSS 6.5
CVE-2023-41175 [MEDIUM] CWE-190 libtiff: potential integer overflow in raw2tiff.c
libtiff: potential integer overflow in raw2tiff.c
A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.
A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.
Package: libtiff (Red Hat Enterprise Linux 6) - Out of support scope
Package: compact-libtiff (Red Hat Enterprise Linux 7) - Out of support scope
Package: libtiff (Red Hat Enterprise Linux 7) - Out of support
Debian
CVE-2023-41175: tiff - A vulnerability was found in libtiff due to multiple potential integer overflows...
vendor_debian·2023·CVSS 6.5
CVE-2023-41175 [MEDIUM] CVE-2023-41175: tiff - A vulnerability was found in libtiff due to multiple potential integer overflows...
A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 4.5.0-6+deb12u1)
bullseye: resolved (fixed in 4.2.0-1+deb11u5)
forky: resolved (fixed in 4.5.1+git230720-1)
sid: resolved (fixed in 4.5.1+git230720-1)
trixie: resolved (fixed in 4.5.1+git230720-1)
No detection rules found.
No public exploits indexed.
arXiv
PortGPT: Towards Automated Backporting Using Large Language Models
arxiv_fulltext·2025-10-25
PortGPT: Towards Automated Backporting Using Large Language Models
: Towards Automated Backporting Using Large Language Models
Zhaoyang Li21,
Zheng Yu31,
Jingyi Song2,
Meng Xu5,
Yuxuan Luo6,
Dongliang Mu24
2School of Cyber Science and Engineering, Huazhong University of Science and Technology, China
2Hubei Key Laboratory of Distributed System Security
3Northwestern University,
5University of Waterloo,
6Canonical Ltd.,
4JinYinHu Laboratory, China
\lizy04, jingyisong, dzm91\@hust.edu.cn
[email protected],
[email protected],
[email protected]
\@makefntext#1 1em #1
1 The first two authors contributed equally (alphabetical order).
Corresponding author
## Abstract
Patch backporting,
the process of migrating mainline security patches to older branches,
is an essential task in maintaining popular open-source projects
(e.g., Linux ke
arXiv
Real-VulLLM: An LLM Based Assessment Framework in the Wild
arxiv_fulltext·2025-10-05
Real-VulLLM: An LLM Based Assessment Framework in the Wild
Real-VulLLM: An LLM Based Assessment Framework in the Wild
Rijha Safdar, Danyail Mateen, Syed Taha Ali and Wajahat Hussain
R. Safdar, S.T. Ali and W. Hussain are with School of Electrical Engineering and Computer Science, National University of Sciences and Technology, Islamabad, Pakistan, 44000. e-mail: [email protected] ,e-mail: [email protected], email:[email protected]
D. Mateen is with the Department
Computer Science, Fast University, Islamabad,
Pakistan, 44000
## Abstract
Artificial Intelligence (AI) and more specifically Large Language Models (LLMs) have demonstrated exceptional progress in multiple areas including software engineering, however, their capability for vulnerability detection in the wild scenario and its corresponding reasoning remains
https://access.redhat.com/errata/RHSA-2024:2289https://access.redhat.com/security/cve/CVE-2023-41175https://bugzilla.redhat.com/show_bug.cgi?id=2235264https://access.redhat.com/errata/RHSA-2024:2289https://access.redhat.com/security/cve/CVE-2023-41175https://bugzilla.redhat.com/show_bug.cgi?id=2235264
2023-10-05
Published