CVE-2023-1916: Race Condition
A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.
Other sources
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
AMD. A race condition was addressed with improved state handling.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppSandbox. A logic issue was addressed with improved restrictions.
— Apple
Credit
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40442
- CVE-2023-34425
- CVE-2023-32364
- CVE-2023-35983
- CVE-2023-40392
- CVE-2023-34241
- CVE-2023-28319
- CVE-2023-28320
- CVE-2023-28321
- CVE-2023-28322
- CVE-2023-32416
- CVE-2023-41990
- CVE-2023-36854
- CVE-2023-32418
- CVE-2023-38603
- CVE-2023-38590
- CVE-2023-38598
- CVE-2023-36495
- CVE-2023-37285
- CVE-2023-38604
- CVE-2023-32381
- CVE-2023-32433
- CVE-2023-35993
- CVE-2023-38606
- CVE-2023-32441
- CVE-2023-38565
- CVE-2023-38593
- CVE-2023-40440
- CVE-2023-38571
- CVE-2023-38421
- CVE-2023-38258
- CVE-2023-1916
- CVE-2023-29491
- CVE-2023-38601
- CVE-2023-32444
- CVE-2023-2953
- CVE-2023-42829
- CVE-2023-38259
- CVE-2023-38602
- CVE-2023-42831
- CVE-2023-32442
- CVE-2023-32443
- CVE-2023-42832
- CVE-2023-32422
- CVE-2023-32429
- CVE-2023-1801
- CVE-2023-2426
- CVE-2023-2609
- CVE-2023-2610
- CVE-2023-38605
- CVE-2023-40439
- CVE-2023-38616
- CVE-2023-38580
- CVE-2023-36862
- CVE-2023-42828
- CVE-2023-40437
- CVE-2022-3970
- CVE-2023-28200
- CVE-2023-32734
- CVE-2023-38261
- CVE-2023-38424
- CVE-2023-38425
- CVE-2023-38410
- CVE-2023-38609
- CVE-2023-38564
- CVE-2023-32654
- CVE-2023-38608
- CVE-2023-40397
- CVE-2023-38572
- CVE-2023-38599
- CVE-2023-32445
- CVE-2023-38592
- CVE-2023-38594
- CVE-2023-38595
- CVE-2023-38600
- CVE-2023-38611
- CVE-2023-37450
- CVE-2023-42866
- CVE-2023-38597
- CVE-2023-38133
- CVE-2023-43000
Frequently Asked Questions
What is CVE-2023-1916?
CVE-2023-1916 is a vulnerability found in the tiffcrop program distributed by the libtiff package.
What is the impact of CVE-2023-1916?
CVE-2023-1916 can lead to an out-of-bounds read in the extractImageSection function, resulting in a denial of service and limited information disclosure.
Which versions of libtiff are affected by CVE-2023-1916?
CVE-2023-1916 affects libtiff versions 4.0.9-5ubuntu0.10+ (bionic), 4.1.0+ (focal), 4.3.0-6ubuntu0.6 (jammy), 4.5.0-5ubuntu1.2 (lunar), 4.0.3-7ubuntu0.11+ (trusty), and 4.0.6-1ubuntu0.8+ (xenial).
How can I fix CVE-2023-1916?
To fix CVE-2023-1916, update the libtiff package to the recommended versions provided by the respective sources (Ubuntu or Debian).
Where can I find more information about CVE-2023-1916?
You can find more information about CVE-2023-1916 at the following references: [MITRE CVE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1916), [Ubuntu Security Notice](https://ubuntu.com/security/notices/USN-6428-1), and [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-1916).