CVE-2023-3576: Libtiff: memory leak in tiffcrop.c
A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, resulting an application crash, eventually leading to a denial of service.
Other sources
A vulnerability was found in libtiff where a memory leak exists in tools/tiffcrop.c.
References: https://gitlab.com/libtiff/libtiff/-/mergerequests/475
— Red Hat
LibTIFF is vulnerable to a denial of service, caused by a memory leak in tiffcrop.c. By persuading a victim to open a specially crafted TIFF image file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/tiffto a version that resolves this vulnerability.Fixed in 4.0.9-5ubuntu0.10+ - Upgrade
Upgrade
ubuntu/tiffto a version that resolves this vulnerability.Fixed in 4.1.0+ - Upgrade
Upgrade
ubuntu/tiffto a version that resolves this vulnerability.Fixed in 4.3.0-6ubuntu0.7 - Upgrade
Upgrade
ubuntu/tiffto a version that resolves this vulnerability.Fixed in 4.0.3-7ubuntu0.11+ - Upgrade
Upgrade
ubuntu/tiffto a version that resolves this vulnerability.Fixed in 4.0.6-1ubuntu0.8+ - Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.2.0-1+deb11u5Fixed in 4.5.0-6+deb12u1Fixed in 4.5.1+git230720-4 - Upgrade
Upgrade
redhat/libtiffto a version that resolves this vulnerability.Fixed in 4.5.1
Event History
Frequently Asked Questions
What is CVE-2023-3576?
CVE-2023-3576 is a memory leak flaw in Libtiff's tiffcrop utility that can lead to an application crash and denial of service.
How does CVE-2023-3576 occur?
CVE-2023-3576 occurs when tiffcrop operates on a crafted TIFF image file, causing a memory leak issue.
What is the severity of CVE-2023-3576?
CVE-2023-3576 has a severity rating of medium with a CVSS score of 5.5.
Which software is affected by CVE-2023-3576?
Libtiff version up to and excluding 4.5.1 is affected, as well as Redhat Enterprise Linux 8.0 and 9.0, and Fedora.
How can I fix CVE-2023-3576?
You can fix CVE-2023-3576 by updating to version 4.5.1 of Libtiff or applying the appropriate patches provided by your operating system vendor.