Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-41175

Опубликовано: 21 июл. 2023
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtiffOut of support scope
Red Hat Enterprise Linux 7compact-libtiffOut of support scope
Red Hat Enterprise Linux 7libtiffOut of support scope
Red Hat Enterprise Linux 8compat-libtiff3Will not fix
Red Hat Enterprise Linux 8libtiffWill not fix
Red Hat Enterprise Linux 8mingw-libtiffWill not fix
Red Hat Enterprise Linux 9libtiffFixedRHSA-2024:228930.04.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2235264libtiff: potential integer overflow in raw2tiff.c

EPSS

Процентиль: 57%
0.0034
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

CVSS3: 6.5
nvd
больше 2 лет назад

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

CVSS3: 6.5
msrc
больше 2 лет назад

Libtiff: potential integer overflow in raw2tiff.c

CVSS3: 6.5
debian
больше 2 лет назад

A vulnerability was found in libtiff due to multiple potential integer ...

CVSS3: 6.5
github
больше 2 лет назад

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

EPSS

Процентиль: 57%
0.0034
Низкий

6.5 Medium

CVSS3