CVE-2023-30774: Buffer Overflow
A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAGINKNAMES and TIFFTAGNUMBEROFINKS values.
Other sources
App Support. This issue was addressed by removing the vulnerable code.
— Apple
heap-buffer-overflow in tiffcrop https://gitlab.com/libtiff/libtiff/-/issues/463
— Red Hat
LibTIFF is vulnerable to a denial of service, caused by a heap-based buffer overflow related to TIFFTAGINKNAMES and TIFFTAGNUMBEROFINKS value. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-30774
- CVE-2023-40444
- CVE-2023-42952
- CVE-2023-42945
- CVE-2023-41072
- CVE-2023-42857
- CVE-2023-40449
- CVE-2023-42823
- CVE-2023-41989
- CVE-2023-42854
- CVE-2023-40413
- CVE-2023-42834
- CVE-2023-42844
- CVE-2023-42953
- CVE-2023-40416
- CVE-2023-42848
- CVE-2023-40423
- CVE-2023-38403
- CVE-2023-42849
- CVE-2023-42850
- CVE-2023-40446
- CVE-2023-42942
- CVE-2023-42861
- CVE-2023-42935
- CVE-2023-40408
- CVE-2023-40405
- CVE-2023-28826
- CVE-2023-42856
- CVE-2023-40404
- CVE-2023-42859
- CVE-2023-42877
- CVE-2023-42840
- CVE-2023-42853
- CVE-2023-42860
- CVE-2023-42889
- CVE-2023-42847
- CVE-2023-42845
- CVE-2023-42841
- CVE-2023-42873
- CVE-2023-42838
- CVE-2023-42835
- CVE-2023-41977
- CVE-2023-42438
- CVE-2023-42836
- CVE-2023-42839
- CVE-2023-42878
- CVE-2023-41982
- CVE-2023-41997
- CVE-2023-41988
- CVE-2023-42946
- CVE-2023-36191
- CVE-2023-40421
- CVE-2023-42842
- CVE-2023-4733
- CVE-2023-4734
- CVE-2023-4735
- CVE-2023-4736
- CVE-2023-4738
- CVE-2023-4750
- CVE-2023-4751
- CVE-2023-4752
- CVE-2023-4781
- CVE-2023-41254
- CVE-2023-40447
- CVE-2023-41976
- CVE-2023-42852
- CVE-2023-42843
- CVE-2023-41983
- CVE-2023-41975
- CVE-2023-42858
Frequently Asked Questions
What is the vulnerability ID for this flaw in the libtiff library?
The vulnerability ID for this flaw in the libtiff library is CVE-2023-30774.
What is the severity of CVE-2023-30774?
CVE-2023-30774 has a severity rating of medium.
How does CVE-2023-30774 manifest?
CVE-2023-30774 manifests as a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROFINKS values.
Which version of the libtiff library is affected by CVE-2023-30774?
The libtiff library version 4.0.0 is affected by CVE-2023-30774.
Are there any known fixes or patches available for CVE-2023-30774?
Yes, the vulnerability has been reported and fixes or patches may be available. It is recommended to check with the vendor or official sources for the latest updates.