USN-6428-1: LibTIFF vulnerability
It was discovered that LibTIFF could be made to read out of bounds when processing certain malformed image files with the tiffcrop utility. If a user were tricked into opening a specially crafted image file, an attacker could possibly use this issue to cause tiffcrop to crash, resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this LibTIFF vulnerability?
The vulnerability ID for this LibTIFF vulnerability is USN-6428-1.
What is the severity of USN-6428-1?
The severity of USN-6428-1 is not specified in the provided information.
How does the LibTIFF vulnerability affect Ubuntu 23.04?
The LibTIFF vulnerability affects Ubuntu 23.04 and requires an update to libtiff-tools version 4.5.0-5ubuntu1.2 or later.
How can I fix the LibTIFF vulnerability in Ubuntu 22.04?
To fix the LibTIFF vulnerability in Ubuntu 22.04, update to libtiff-tools version 4.3.0-6ubuntu0.6 or later.
Where can I find more information about the LibTIFF vulnerability?
More information about the LibTIFF vulnerability can be found at the following references: [CVE-2023-1916](https://ubuntu.com/security/CVE-2023-1916), [Ubuntu Security Notice](https://ubuntu.com/security/notices/USN-6428-1), [LibTIFF Launchpad](https://launchpad.net/ubuntu/+source/tiff/4.5.0-5ubuntu1.2), [LibTIFF Launchpad](https://launchpad.net/ubuntu/+source/tiff/4.3.0-6ubuntu0.6).