First published: Wed Sep 27 2023(Updated: )
An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/tiff | <=4.2.0-1+deb11u5<=4.5.0-6+deb12u1<=4.5.1+git230720-5 | |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
All of | ||
TIFF | ||
Any of | ||
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Enterprise Linux | =8.0 | |
Red Hat Enterprise Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6228 is classified as a high-severity vulnerability due to the potential for a heap-based buffer overflow.
You can fix CVE-2023-6228 by applying the recommended patches provided by the affected software vendors.
CVE-2023-6228 affects libtiff versions up to and including 4.2.0-1+deb11u5, 4.5.0-6+deb12u1, and 4.5.1+git230720-5.
Yes, CVE-2023-6228 affects IBM Cognos Analytics versions up to 12.0.0-12.0.3 and 11.2.0-11.2.4 FP4.
CVE-2023-6228 can lead to application crashes, which may disrupt services relying on the affected software.