CVE-2023-25435: Buffer Overflow
libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesShifted8bits() at /libtiff/tools/tiffcrop.c:3753.
Other sources
LibTIFF is vulnerable to a denial of service, caused by a heap-based buffer overflow in the extractContigSamplesShifted8bits() function at /libtiff/tools/tiffcrop.c. By persuading a victim to open a specially crafted tiff file, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-25435.
What software version is affected by the vulnerability?
The vulnerability affects libtiff version 4.5.0.
What is the severity of the vulnerability?
The vulnerability has a severity of medium, with a severity value of 5.5.
How does the vulnerability occur?
The vulnerability occurs through a buffer overflow in the function extractContigSamplesShifted8bits() at /libtiff/tools/tiffcrop.c:3753.
Is there a fix available for the vulnerability?
Currently, there is no fix available for the vulnerability. It is recommended to update to a patched version when it becomes available.