Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-52355

Опубликовано: 25 янв. 2024
Источник: debian

Описание

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tifffixed4.5.1+git230720-4package
tiffignoredbookwormpackage
tiffignoredbullseyepackage
tiffignoredbusterpackage

Примечания

  • https://gitlab.com/libtiff/libtiff/-/issues/621

  • https://gitlab.com/libtiff/libtiff/-/merge_requests/553

  • https://gitlab.com/libtiff/libtiff/-/commit/335947359ce2dd3862cd9f7c49f92eba065dfed4

  • https://gitlab.com/libtiff/libtiff/-/commit/16ab4a205cfc938c32686e8d697d048fabf97ed4

  • Issue fixed by providing a documentation update

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVSS3: 7.5
redhat
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVSS3: 7.5
nvd
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

msrc
11 месяцев назад

Libtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom

CVSS3: 7.5
github
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.