CVE-2023-1916

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
10/04/2023
Last modified:
23/12/2023

Description

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:* 4.0 (including) 4.5.0 (including)