First published: Mon Aug 28 2023(Updated: )
LibTIFF is vulnerable to a denial of service, caused by an integer overflow in tiffcp.c. By persuading a victim to open a specially crafted tiff image file, a remote attacker could exploit this vulnerability to cause the application to crash.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libtiff | <4.6.0 | 4.6.0 |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
TIFF | <4.6.0 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
Red Hat Fedora | ||
Red Hat Enterprise Linux | =8.0 | |
Red Hat Enterprise Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40745 is a vulnerability in LibTIFF that allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted tiff image.
CVE-2023-40745 affects LibTIFF versions up to but excluding version 4.6.0.
The severity level of CVE-2023-40745 is medium, with a CVSS score of 6.5.
To fix CVE-2023-40745, update LibTIFF to version 4.6.0 or later.
You can find more information about CVE-2023-40745 in the following references: [Bugzilla Red Hat - ID 2224974](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2224974), [Bugzilla Red Hat - ID 2237199](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2237199), [Bugzilla Red Hat - ID 2237200](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2237200).