CVE-2023-25433: Buffer Overflow
Last updated 24 July 2024
Other sources
libtiff 4.5.0 is vulnerable to Buffer Overflow via /libtiff/tools/tiffcrop.c:8499. Incorrect updating of buffer size after rotateImage() in tiffcrop cause heap-buffer-overflow and SEGV.
— Launchpad
LibTIFF is vulnerable to a denial of service, caused by a heap-based buffer overflow in /libtiff/tools/tiffcrop.c. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-25433.
What software versions are affected by this vulnerability?
libtiff 4.5.0 is affected by this vulnerability.
What is the severity level of CVE-2023-25433?
The severity level of CVE-2023-25433 is medium with a severity value of 5.5.
How does the vulnerability manifest?
The vulnerability manifests as a buffer overflow in the tiffcrop tool of libtiff 4.5.0.
Is there a fix available for this vulnerability?
Yes, the fix for this vulnerability is available in versions 4.1.0+git191117-2~deb10u8 and 4.5.1+git230720-1 of the tiff package.