CVE-2023-0796: Medium severity ibm cognos analytics vulnerability
LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3592, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.
Other sources
LibTIFF is vulnerable to a denial of service, caused by a segmentation fault when processing TIFF files in extractContigSamplesShifted24bits in tools/tiffcrop.c. By persuading a victim to open a specially-crafted TIFF file, a remote attacker could overflow a buffer and cause a denial of service.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-0796?
CVE-2023-0796 is a vulnerability in LibTIFF 4.4.0 that allows attackers to cause a denial-of-service via a crafted TIFF file.
What is the severity of CVE-2023-0796?
CVE-2023-0796 has a severity level of medium.
How can attackers exploit CVE-2023-0796?
Attackers can exploit CVE-2023-0796 by using a crafted TIFF file to trigger an out-of-bounds read in the tiffcrop tool.
How can I fix CVE-2023-0796?
To fix CVE-2023-0796, users that compile libtiff from sources can apply the fix available with commit afaabc3e.
Where can I find more information about CVE-2023-0796?
You can find more information about CVE-2023-0796 on the GitLab page and the Debian security tracker page provided in the references.