Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-52355

Опубликовано: 03 нояб. 2023
Источник: redhat
CVSS3: 7.5

Описание

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

Отчет

The identified out-of-memory vulnerability in libtiff, triggered by a crafted TIFF file passed to the TIFFRasterScanlineSize64() API, presents a moderate severity concern rather than a important one due to several factors. Primarily, the exploit requires the crafted input to be smaller than 379 KB, imposing a limitation on the potential impact and reducing the likelihood of successful exploitation in practical scenarios. Furthermore, the nature of the vulnerability is limited to denial-of-service attacks, which, although disruptive, do not inherently pose a direct risk of data compromise or system compromise. However, it's important to acknowledge that denial-of-service attacks can still have significant operational implications, particularly in environments reliant on continuous availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtiffOut of support scope
Red Hat Enterprise Linux 7compat-libtiff3Out of support scope
Red Hat Enterprise Linux 7libtiffOut of support scope
Red Hat Enterprise Linux 8compat-libtiff3Will not fix
Red Hat Enterprise Linux 8libtiffAffected
Red Hat Enterprise Linux 10libtiffFixedRHSA-2026:4189220.07.2026
Red Hat Enterprise Linux 9libtiffFixedRHSA-2025:2080111.11.2025
Red Hat Enterprise Linux 9.6 Extended Update SupportlibtiffFixedRHSA-2026:4353722.07.2026
Red Hat AI Inference Server 3.2rhaiis/vllm-cuda-rhel9FixedRHSA-2025:2307810.12.2025
Red Hat AI Inference Server 3.2rhaiis/vllm-rocm-rhel9FixedRHSA-2025:2307910.12.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2251326libtiff: TIFFRasterScanlineSize64 produce too-big size and could cause OOM

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVSS3: 7.5
nvd
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

msrc
11 месяцев назад

Libtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom

CVSS3: 7.5
debian
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by ...

CVSS3: 7.5
github
больше 2 лет назад

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

7.5 High

CVSS3