CVE-2023-0801

Published: 02/13/2023 23:15:12
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6778, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
MEDIUM
CVSS v3: 6.8

Status

DocFilters Release Package State Justification Comment
25.1 libtiff (4.6.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
24.4 libtiff (4.6.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
24.4.0 libtiff (4.6.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
24.3 libtiff (4.6.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
24.2.1 libtiff (4.6.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
24.2 libtiff (4.6.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
24.1 libtiff (4.6.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
23.3 libtiff (4.5.1) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
23.2.1 libtiff (4.3.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
23.2 libtiff (4.3.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
23.1 libtiff (4.3.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
22.4 libtiff (4.3.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
22.3 libtiff (4.3.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
22.2 libtiff (4.3.0) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
22.1 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
21.11.1 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
21.11 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
21.8.1 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
21.8 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
21.5.1 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
21.5.0 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
21.2.0 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.20 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.19.3667 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.18.3599 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.17 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.16.3445 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.15.3368 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.14.3263 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.13.3179 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.12.3054 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.11.3040 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.11.2990 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.10.2934 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.9.2878 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.
11.4.8.2822 libtiff (4.0.8) Not Affected Code Not Present Vulnerability is in tiff CLI tool tiffcrop; code is not compiled into Document Filters. There were no modifications to tif_unix.c in provided commit.

Severity score breakdown

Attack Complexity
LOW
Attack Vector
LOCAL
Availability Impact
HIGH
Base Score
6.8
Base Severity
MEDIUM
Confidentiality Impact
NONE
Integrity Impact
LOW
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Version
3.1

References