CVE-2023-1916
CVSS V2 None
CVSS V3 None
Description
A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.
Overview
- CVE ID
- CVE-2023-1916
- Assigner
- secalert@redhat.com
- Vulnerability Status
- Analyzed
- Published Version
- 2023-04-10T22:15:09
- Last Modified Date
- 2023-04-18T15:25:08
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:* | 1 | OR | 4.0 | 4.5.0 |
References
Reference URL | Reference Tags |
---|---|
https://gitlab.com/libtiff/libtiff/-/issues/536 | Exploit Issue Tracking |
https://gitlab.com/libtiff/libtiff/-/issues/536, | Permissions Required |
https://gitlab.com/libtiff/libtiff/-/issues/537 | Exploit Issue Tracking |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-1916 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1916 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 04:27:55 | Added to TrackCVE | |||
2023-04-17 04:27:56 | Weakness Enumeration | new | ||
2023-04-18 16:00:35 | 2023-04-18T15:25:08 | CVE Modified Date | updated | |
2023-04-18 16:00:35 | Undergoing Analysis | Analyzed | Vulnerability Status | updated |
2023-04-18 16:00:38 | CPE Information | updated | ||
2023-04-18 16:00:38 | References | updated |