CVE-2023-40745
Summary
| CVE | CVE-2023-40745 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-05 19:15:00 UTC |
| Updated | 2023-11-10 18:15:00 UTC |
| Description | LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296108 Oracle Solaris 11.4 Support Repository Update (SRU) 66.164.1 Missing (CPUJAN2024)
- 356375 Amazon Linux Security Advisory for libtiff : ALAS2023-2023-364
- 6000095 Debian Security Update for tiff (DLA 3513-1)
- 6000353 Debian Security Update for tiff (DSA 5567-1)
- 673711 EulerOS Security Update for libtiff (EulerOS-SA-2024-1148)
- 755986 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2024:0915-1)
- 755990 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2024:0973-1)
- 907570 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (31096-1)