CVE-2023-52356: Libtiff: segment fault in libtiff in tiffreadrgbatileext() leading to denial of service
A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.
Other sources
A Segment fault (SEGV) problem was found in libtiff that could be triggered by passing a craft tiff file to TIFFReadRGBATileExt() API. In this flaw a remote attackers could cause a Heap-buffer-overflow problem leading to a denial of service.
Reference: https://gitlab.com/libtiff/libtiff/-/issues/622
Fixed at: https://gitlab.com/libtiff/libtiff/-/mergerequests/546
— Red Hat
Accounts. The issue was addressed with improved checks.
— Apple
AirDrop. This issue was addressed through improved state management.
— Apple
apache. This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
— Apple
APFS. The issue was addressed with improved restriction of data container access.
— Apple
Credit
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-40804
- CVE-2023-38709
- CVE-2024-24795
- CVE-2024-27316
- CVE-2024-40783
- CVE-2024-40774
- CVE-2024-40814
- CVE-2024-40775
- CVE-2024-27877
- CVE-2024-27878
- CVE-2024-40799
- CVE-2024-27873
- CVE-2024-2004
- CVE-2024-2379
- CVE-2024-2398
- CVE-2024-2466
- CVE-2024-40827
- CVE-2024-40815
- CVE-2024-40795
- CVE-2023-6277
- CVE-2023-52356
- CVE-2024-40806
- CVE-2024-40777
- CVE-2024-40784
- CVE-2024-27863
- CVE-2024-40816
- CVE-2024-40788
- CVE-2024-40803
- CVE-2024-40805
- CVE-2024-40832
- CVE-2024-40796
- CVE-2024-6387
- CVE-2024-40781
- CVE-2024-40802
- CVE-2024-40823
- CVE-2024-27882
- CVE-2024-27883
- CVE-2024-40778
- CVE-2024-40800
- CVE-2023-27952
- CVE-2024-40817
- CVE-2024-40824
- CVE-2024-27871
- CVE-2024-27881
- CVE-2024-40821
- CVE-2024-40798
- CVE-2024-27872
- CVE-2024-27862
- CVE-2024-40833
- CVE-2024-40835
- CVE-2024-40836
- CVE-2024-40807
- CVE-2024-40834
- CVE-2024-40809
- CVE-2024-40812
- CVE-2024-40787
- CVE-2024-40793
- CVE-2024-40818
- CVE-2024-40822
- CVE-2024-40828
- CVE-2024-40811
- CVE-2024-40776
- CVE-2024-40782
- CVE-2024-40779
- CVE-2024-40780
- CVE-2024-40785
- CVE-2024-40789
- CVE-2024-4558
- CVE-2024-40794
- CVE-2024-40813
- CVE-2024-40829
- CVE-2024-27826
- CVE-2024-27804
- CVE-2024-27823
- CVE-2024-23296
- CVE-2024-44205
- CVE-2024-23261
- CVE-2024-40786
- CVE-2024-54551
- CVE-2024-44185
- CVE-2024-44206
- CVE-2024-54564
- CVE-2024-44306
- CVE-2024-44307
- CVE-2024-44141
- CVE-2024-44199
- CVE-2024-40810
- CVE-2024-44305
- CVE-2024-40865
Frequently Asked Questions
What is the severity of CVE-2023-52356?
CVE-2023-52356 has a high severity due to the potential for a heap-buffer overflow leading to a denial of service.
How do I fix CVE-2023-52356?
To fix CVE-2023-52356, update the affected software packages to their respective patched versions as recommended by the vendor.
What products are affected by CVE-2023-52356?
CVE-2023-52356 affects various Apple products including visionOS, watchOS, macOS Monterey, tvOS, iOS, and iPadOS, as well as IBM's Cognos Analytics and the tiff package in Debian.
Can CVE-2023-52356 be exploited remotely?
Yes, CVE-2023-52356 can be exploited remotely by attackers using malicious TIFF files.
What kind of vulnerability is CVE-2023-52356 classified as?
CVE-2023-52356 is classified as a segment fault vulnerability that leads to potential heap-buffer overflow.