Описание
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
A flaw was found in tiffcp, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the tiffcp function in tools/tiffcp.c, resulting in a denial of service and limited information disclosure.
Отчет
libtiff is a general purpose library to manipulate TIFF images. The library itself is not used directly, it's used via another application linked with the library, which means this issue can only be triggered by an application processing untrusted images. Therefore, if there is no way an attacker can provide a crafted image to an application, it's likely not possible to exploit this CVE.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | libtiff | Out of support scope | ||
Red Hat Enterprise Linux 7 | compat-libtiff3 | Out of support scope | ||
Red Hat Enterprise Linux 7 | libtiff | Out of support scope | ||
Red Hat Enterprise Linux 8 | compat-libtiff3 | Will not fix | ||
Red Hat Enterprise Linux 8 | libtiff | Fixed | RHSA-2024:3059 | 22.05.2024 |
Red Hat Enterprise Linux 9 | libtiff | Fixed | RHSA-2023:2340 | 09.05.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.6 Medium
CVSS3
Связанные уязвимости
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:94 ...
EPSS
5.6 Medium
CVSS3