CVE-2023-26966: Buffer Overflow
Published Jun 29, 2023
·Updated
Last updated 24 July 2024
Other sources
libtiff 4.5.0 is vulnerable to Buffer Overflow in uvencode() when libtiff reads a corrupted little-endian TIFF file and specifies the output to be big-endian.
— Launchpad
Affected Software
6 affected componentsFixes available
debian/tiff<=4.2.0-1+deb11u5, <=4.5.0-6+deb12u1
4.5.1+git230720-5
LibTIFF libtiff=4.5.0
IBM Datacap<=9.1.7
IBM Datacap<=9.1.9
IBM Datacap<=9.1.8
IBM Datacap Navigator<=All
Remediation
Patch Available
Patch Available
Event History
Jun 29, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 30, 2023
Data Sourced
via Red Hat·06:07 AM
DescriptionSeverityAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:17 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:17 AM
RemedyDescriptionSeverityAffected Software
Jun 27, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2023-26966?
CVE-2023-26966 is a vulnerability in libtiff 4.5.0 that allows a buffer overflow when reading a corrupted little-endian TIFF file.
2
How does libtiff 4.5.0 become vulnerable to CVE-2023-26966?
libtiff 4.5.0 becomes vulnerable to CVE-2023-26966 when it reads a corrupted little-endian TIFF file and specifies the output to be big-endian.
3
What is the severity of CVE-2023-26966?
The severity of CVE-2023-26966 is medium, with a severity value of 5.5.
4
Which software versions are affected by CVE-2023-26966?
The affected software versions include libtiff 4.5.0 and earlier versions up to 4.5.0-6.
5
How can I mitigate CVE-2023-26966?
To mitigate CVE-2023-26966, update to a patched version of libtiff, such as 4.5.1 or later.