CVE-2023-6228: Libtiff: heap-based buffer overflow in cpstriptotile() in tools/tiffcp.c
An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.
Other sources
An issue was found in the tiffcp utility distributed by the libtiff package. Processing a crafted TIFF file may cause a heap-based buffer overflow, resulting in an application crash.
Reference: https://gitlab.com/libtiff/libtiff/-/issues/606
— Red Hat
LibTIFF is vulnerable to a denial of service, caused by a heap-based buffer overflow in cpStripToTile() function in tools/tiffcp.c. By persuading a victim to open a specially crafted content, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6228?
CVE-2023-6228 is classified as a high-severity vulnerability due to the potential for a heap-based buffer overflow.
How do I fix CVE-2023-6228?
You can fix CVE-2023-6228 by applying the recommended patches provided by the affected software vendors.
Which versions of libtiff are affected by CVE-2023-6228?
CVE-2023-6228 affects libtiff versions up to and including 4.2.0-1+deb11u5, 4.5.0-6+deb12u1, and 4.5.1+git230720-5.
Does CVE-2023-6228 affect IBM Cognos Analytics?
Yes, CVE-2023-6228 affects IBM Cognos Analytics versions up to 12.0.0-12.0.3 and 11.2.0-11.2.4 FP4.
What kind of impact can CVE-2023-6228 have on affected systems?
CVE-2023-6228 can lead to application crashes, which may disrupt services relying on the affected software.