CVE-2023-38289: Integer Overflow
Published Aug 24, 2023
·Updated
REJECT Not a Security Issue.
Other sources
LibTIFF is vulnerable to a denial of service, caused by an integer overflow in tiffcp.c. By persuading a victim to open a a specially crafted content, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
2 affected componentsFixes available
IBM Cognos Analytics<=12.0.0-12.0.3
IBM Cognos Analytics<=11.2.0-11.2.4 FP4
Remediation
Event History
Aug 24, 2023
CVE Published
09:15 AM
Rejected
09:15 AM
Data Sourced
09:15 AM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:22 AM
Description
Data Sourced
via Debian·12:23 AM
DescriptionAffected Software
Sep 16, 2024
Data Sourced
via Ubuntu·02:17 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
Is CVE-2023-38289 a security issue?
No, it is not a security issue.
2
What versions of the tiff package are affected by CVE-2023-38289?
The versions affected are 4.0.3-7ubuntu0.11+ (trusty), 4.0.6-1ubuntu0.8+ (xenial), 4.0.9-5ubuntu0.10+ (bionic), 4.1.0+ (focal), 4.3.0-6ubuntu0.5 (jammy), 4.5.0-5ubuntu1.1 (lunar), and 4.5.1+ (upstream).
3
How can I fix the CVE-2023-38289 vulnerability?
The recommended fix for CVE-2023-38289 is to update the tiff package to version 4.1.0+ or later.
4
Where can I find more information about CVE-2023-38289?
You can find more information about CVE-2023-38289 at the following references: [1] [2] [3].
5
What is the Common Weakness Enumeration (CWE) for CVE-2023-38289?
The CWE for CVE-2023-38289 is CWE-190.