CVE-2023-30774

Published: 05/19/2023 15:15:08
A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROFINKS values.
MEDIUM
CVSS v3: 5.5

Status

DocFilters Release Package State Justification Comment
25.1 libtiff (4.6.0) Not Affected Code Not Present
24.4 libtiff (4.6.0) Not Affected Code Not Present
24.4.0 libtiff (4.6.0) Not Affected Code Not Present
24.3 libtiff (4.6.0) Not Affected Code Not Present
24.2.1 libtiff (4.6.0) Not Affected Code Not Present
24.2 libtiff (4.6.0) Not Affected Code Not Present
24.1 libtiff (4.6.0) Not Affected Code Not Present
23.3 libtiff (4.5.1) Not Affected Code Not Present
23.2.1 libtiff (4.3.0) Needs Triage
23.2 libtiff (4.3.0) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
23.1 libtiff (4.3.0) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
22.4 libtiff (4.3.0) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
22.3 libtiff (4.3.0) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
22.2 libtiff (4.3.0) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
22.1 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
21.11.1 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
21.11 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
21.8.1 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
21.8 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
21.5.1 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
21.5.0 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
21.2.0 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.20 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.19.3667 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.18.3599 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.17 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.16.3445 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.15.3368 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.14.3263 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.13.3179 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.12.3054 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.11.3040 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.11.2990 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.10.2934 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.9.2878 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.
11.4.8.2822 libtiff (4.0.8) Exploitable A crafted TIFF may cause this issue when converting the file to hi-def. Does not impacted indentification or text-extraction, unless OCR is enabled.

Severity score breakdown

Attack Complexity
LOW
Attack Vector
LOCAL
Availability Impact
HIGH
Base Score
5.5
Base Severity
MEDIUM
Confidentiality Impact
NONE
Integrity Impact
NONE
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Version
3.1

References