CVE-2023-3316
Summary
| CVE | CVE-2023-3316 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-19 12:15:00 UTC |
| Updated | 2023-08-01 02:15:00 UTC |
| Description | A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones. |
Risk And Classification
Problem Types: CWE-476
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TIFFClose() avoid NULL pointer dereferencing. fix#515 (!468) · Merge requests · libtiff / libtiff · GitLab | MISC | gitlab.com | |
| libtiff NULL dereference DoS | XRAY-522144 - JFrog Security Research | MISC | research.jfrog.com | |
| Null Pointer Dereference in TIFFClose() (#515) · Issues · libtiff / libtiff · GitLab | MISC | gitlab.com | |
| [SECURITY] [DLA 3513-1] tiff security update | MISC | lists.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161060 Oracle Enterprise Linux Security Update for libtiff (ELSA-2023-6575)
- 199523 Ubuntu Security Notification for LibTIFF Vulnerabilities (USN-6229-1)
- 199657 Ubuntu Security Notification for LibTIFF Vulnerabilities (USN-6290-1)
- 242305 Red Hat Update for libtiff (RHSA-2023:6575)
- 296105 Oracle Solaris 11.4 Support Repository Update (SRU) 63.157.1 Missing (CPUOCT2023)
- 355580 Amazon Linux Security Advisory for compat-libtiff3 : ALAS2-2023-2125
- 355581 Amazon Linux Security Advisory for libtiff : ALAS2-2023-2126
- 355752 Amazon Linux Security Advisory for libtiff : ALAS2023-2023-267
- 356353 Amazon Linux Security Advisory for libtiff : ALAS-2023-1846
- 356972 Amazon Linux Security Advisory for libtiff : AL2012-2023-456
- 503038 Alpine Linux Security Update for tiff
- 6000095 Debian Security Update for tiff (DLA 3513-1)
- 673434 EulerOS Security Update for libtiff (EulerOS-SA-2023-2861)
- 673527 EulerOS Security Update for libtiff (EulerOS-SA-2023-2881)
- 673689 EulerOS Security Update for libtiff (EulerOS-SA-2023-2789)
- 673722 EulerOS Security Update for libtiff (EulerOS-SA-2023-2900)
- 673805 EulerOS Security Update for libtiff (EulerOS-SA-2023-3135)
- 673907 EulerOS Security Update for libtiff (EulerOS-SA-2023-2813)
- 673960 EulerOS Security Update for libtiff (EulerOS-SA-2023-2844)
- 755233 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2023:4371-1)
- 755234 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2023:4370-1)
- 907050 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (27212-1)
- 907103 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (27205-1)
- 941373 AlmaLinux Security Update for libtiff (ALSA-2023:6575)