CVE-2023-30775: Buffer Overflow
A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c.
Other sources
Heap buffer overflow in extractContigSamples32bits, tiffcrop.c
https://gitlab.com/libtiff/libtiff/-/issues/464
— Red Hat
libtiff is vulnerable to a denial of service, caused by a heap-based buffer overflow in extractContigSamples32bits in tiffcrop.c. By using a specially crafted file, a local attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-30775.
What is the severity of CVE-2023-30775?
CVE-2023-30775 has a severity of medium (5.5).
Which software is affected by CVE-2023-30775?
The libtiff library version 4.4.0 is affected by CVE-2023-30775.
What is the CWE ID of CVE-2023-30775?
The CWE ID of CVE-2023-30775 is CWE-119 and CWE-787.
How can I fix CVE-2023-30775?
To fix CVE-2023-30775, update to a version of the libtiff library that is not affected, if available, or apply any patches or security updates provided by the software vendor.