CVE-2023-3576
Summary
| CVE | CVE-2023-3576 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-04 19:15:00 UTC |
| Updated | 2024-03-11 13:15:00 UTC |
| Description | A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, resulting an application crash, eventually leading to a denial of service. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161060 Oracle Enterprise Linux Security Update for libtiff (ELSA-2023-6575)
- 199947 Ubuntu Security Notification for LibTIFF Vulnerabilities (USN-6512-1)
- 242305 Red Hat Update for libtiff (RHSA-2023:6575)
- 355678 Amazon Linux Security Advisory for libtiff : ALAS-2023-1788
- 355684 Amazon Linux Security Advisory for compat-libtiff3 : ALAS2-2023-2157
- 355690 Amazon Linux Security Advisory for libtiff : ALAS2-2023-2158
- 355753 Amazon Linux Security Advisory for libtiff : ALAS2023-2023-265
- 6000353 Debian Security Update for tiff (DSA 5567-1)
- 6000519 Debian Security Update for tiff (DLA 3758-1)
- 673434 EulerOS Security Update for libtiff (EulerOS-SA-2023-2861)
- 673527 EulerOS Security Update for libtiff (EulerOS-SA-2023-2881)
- 673689 EulerOS Security Update for libtiff (EulerOS-SA-2023-2789)
- 673722 EulerOS Security Update for libtiff (EulerOS-SA-2023-2900)
- 673805 EulerOS Security Update for libtiff (EulerOS-SA-2023-3135)
- 673907 EulerOS Security Update for libtiff (EulerOS-SA-2023-2813)
- 673960 EulerOS Security Update for libtiff (EulerOS-SA-2023-2844)
- 755233 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2023:4371-1)
- 755234 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2023:4370-1)
- 941373 AlmaLinux Security Update for libtiff (ALSA-2023:6575)