CVE-2023-52355: Libtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
Other sources
An out-of-memory problem was found in libtiff that could be triggered by passing a craft tiff file to TIFFRasterScanlineSize64() API. In this flaw a remote attackers could cause deny-of-services via a craft input (with size smaller than 379 KB).
Reference: https://gitlab.com/libtiff/libtiff/-/issues/621
Fixed at: https://gitlab.com/libtiff/libtiff/-/mergerequests/553 https://gitlab.com/libtiff/libtiff/-/commit/6791bff9f76c2a7f2f18c80b95c796e93fae6a34
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52355?
CVE-2023-52355 has been classified as a moderate severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2023-52355?
To fix CVE-2023-52355, updating libtiff to version 4.6.0 or later is recommended.
What platforms are affected by CVE-2023-52355?
CVE-2023-52355 affects libtiff versions before 4.6.0 and Red Hat Enterprise Linux versions 8.0 and 9.0.
What type of vulnerability is CVE-2023-52355?
CVE-2023-52355 is an out-of-memory flaw that can be exploited through specially crafted TIFF files.
Can CVE-2023-52355 be exploited remotely?
Yes, CVE-2023-52355 can be exploited remotely via a crafted TIFF file that triggers the out-of-memory error.