Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-26965

Опубликовано: 14 июн. 2023
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.

A heap use-after-free vulnerability was found in LibTIFF's tiffcrop utility in the loadImage() function. This flaw allows an attacker to pass a crafted TIFF image file to the tiffcrop utility, which causes an out-of-bounds write access, resulting in an application crash, eventually leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtiffNot affected
Red Hat Enterprise Linux 7compat-libtiff3Not affected
Red Hat Enterprise Linux 7libtiffNot affected
Red Hat Enterprise Linux 8compat-libtiff3Not affected
Red Hat Enterprise Linux 8libtiffWill not fix
Red Hat Enterprise Linux 9libtiffFixedRHSA-2023:657507.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2215206libtiff: heap-based use after free via a crafted TIFF image in loadImage() in tiffcrop.c

EPSS

Процентиль: 1%
0.00008
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.

CVSS3: 5.5
nvd
почти 3 года назад

loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.

CVSS3: 5.5
msrc
почти 3 года назад

loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.

CVSS3: 5.5
debian
почти 3 года назад

loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-ba ...

CVSS3: 8.8
github
почти 3 года назад

loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.

EPSS

Процентиль: 1%
0.00008
Низкий

5.5 Medium

CVSS3