CVE-2023-40745: Libtiff: integer overflow in tiffcp.c
LibTIFF is vulnerable to a denial of service, caused by an integer overflow in tiffcp.c. By persuading a victim to open a specially crafted tiff image file, a remote attacker could exploit this vulnerability to cause the application to crash.
Other sources
LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.
— NVD
Multiple potential integer overflow in tiffcp.c in libtiff <= 4.5.1 can allow remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image which triggers a heap-based buffer overflow.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40745?
CVE-2023-40745 is a vulnerability in LibTIFF that allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted tiff image.
How does CVE-2023-40745 affect LibTIFF?
CVE-2023-40745 affects LibTIFF versions up to but excluding version 4.6.0.
What is the severity level of CVE-2023-40745?
The severity level of CVE-2023-40745 is medium, with a CVSS score of 6.5.
How can I fix CVE-2023-40745?
To fix CVE-2023-40745, update LibTIFF to version 4.6.0 or later.
Where can I find more information about CVE-2023-40745?
You can find more information about CVE-2023-40745 in the following references: [Bugzilla Red Hat - ID 2224974](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2224974), [Bugzilla Red Hat - ID 2237199](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2237199), [Bugzilla Red Hat - ID 2237200](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2237200).