CVE-2023-0802: Buffer Overflow
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3724, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
Other sources
LibTIFF is vulnerable to a denial of service, caused by a heap-based buffer overflow when processing TIFF files in extractContigSamplesShifted32bits in tools/tiffcrop.c. By persuading a victim to open a specially-crafted TIFF file, a remote attacker could overflow a buffer and cause a denial of service.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-0802?
CVE-2023-0802 is a vulnerability in LibTIFF 4.4.0 that allows attackers to cause a denial-of-service via a crafted TIFF file.
How severe is CVE-2023-0802?
CVE-2023-0802 has a severity score of 5.5, which is considered medium severity.
Which software versions are affected by CVE-2023-0802?
LibTIFF versions up to and including 4.4.0, as well as certain versions of the Debian package 'tiff', are affected by CVE-2023-0802.
How can I fix CVE-2023-0802?
If you compile libtiff from sources, you can fix CVE-2023-0802 by applying commit 33aee127. For Debian users, updated versions of the 'tiff' package are available. Please refer to the references for more details.
Where can I find more information about CVE-2023-0802?
You can find more information about CVE-2023-0802 in the provided references.