CVE-2023-3576

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/10/2023
Last modified:
16/09/2024

Description

A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, resulting an application crash, eventually leading to a denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:* 4.5.1 (excluding)
cpe:2.3:o:fedoraproject:fedora:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*