First published: Mon Apr 17 2023(Updated: )
A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libtiff Libtiff | =4.4.0 | |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-30775.
CVE-2023-30775 has a severity of medium (5.5).
The libtiff library version 4.4.0 is affected by CVE-2023-30775.
The CWE ID of CVE-2023-30775 is CWE-119 and CWE-787.
To fix CVE-2023-30775, update to a version of the libtiff library that is not affected, if available, or apply any patches or security updates provided by the software vendor.