CVE-2023-0796
Summary
| CVE | CVE-2023-0796 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-13 23:15:00 UTC |
| Updated | 2023-05-30 06:16:00 UTC |
| Description | LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3592, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-5361-1 tiff | DEBIAN | www.debian.org | |
| 2023/CVE-2023-0796.json · master · GitLab.org / cves · GitLab | CONFIRM | gitlab.com | |
| March 2023 LibTIFF Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| [SECURITY] [DLA 3333-1] tiff security update | MLIST | lists.debian.org | |
| LibTIFF: Multiple Vulnerabilities (GLSA 202305-31) — Gentoo security | GENTOO | security.gentoo.org | |
| Merge branch 'tiffcrop_R270_fix#492' into 'master' (afaabc3e) · Commits · libtiff / libtiff · GitLab | MISC | gitlab.com | |
| tiffcrop: SEGV in extractContigSamplesShifted24bits, tiffcrop.c:3592 (#499) · Issues · libtiff / libtiff · GitLab | MISC | gitlab.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: [email protected]
Legacy QID Mappings
- 160748 Oracle Enterprise Linux Security Update for libtiff (ELSA-2023-3711)
- 181600 Debian Security Update for tiff (DLA 3333-1)
- 181682 Debian Security Update for tiff (DSA 5361-1)
- 182098 Debian Security Update for tiff (CVE-2023-0796)
- 199216 Ubuntu Security Notification for LibTIFF Vulnerabilities (USN-5923-1)
- 241737 Red Hat Update for libtiff (RHSA-2023:3711)
- 356163 Amazon Linux Security Advisory for libtiff : ALAS-2023-1830
- 502796 Alpine Linux Security Update for tiff
- 503026 Alpine Linux Security Update for tiff
- 503134 Alpine Linux Security Update for tiff
- 503693 Alpine Linux Security Update for tiff
- 505947 Alpine Linux Security Update for tiff
- 672867 EulerOS Security Update for libtiff (EulerOS-SA-2023-1599)
- 672968 EulerOS Security Update for libtiff (EulerOS-SA-2023-1874)
- 672998 EulerOS Security Update for libtiff (EulerOS-SA-2023-1849)
- 673036 EulerOS Security Update for libtiff (EulerOS-SA-2023-1957)
- 673055 EulerOS Security Update for libtiff (EulerOS-SA-2023-1979)
- 673076 EulerOS Security Update for libtiff (EulerOS-SA-2023-2157)
- 673143 EulerOS Security Update for libtiff (EulerOS-SA-2023-2298)
- 673160 EulerOS Security Update for libtiff (EulerOS-SA-2023-2274)
- 710734 Gentoo Linux LibTIFF Multiple Vulnerabilities (GLSA 202305-31)
- 754055 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2023:2321-1)
- 754062 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2023:2334-1)
- 905498 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13380)
- 905523 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13390)
- 906310 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13390-1)
- 906529 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13390-2)
- 906551 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13380-1)
- 906572 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13380-3)
- 906659 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13390-4)
- 941151 AlmaLinux Security Update for libtiff (ALSA-2023:3711)