CVE-2023-52355
Published: January 25th, 2024
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
HIGH
CVSS v3: 7.5
CVSS v3: 7.5
Status
| DocFilters Release | Package | State | Justification | Comment |
|---|---|---|---|---|
| 0.0.0.1 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 26.1.1 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 26.1 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 25.4 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 25.3 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 25.2 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 25.1.2 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 25.1.1 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 25.1 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 24.4 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 24.4.0 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 24.3 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 24.2.1 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 24.2 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 24.1 | libtiff (4.6.0) | Not Affected | Code Not Present | 4.6.0 does not match CVE configuration. |
| 23.3 | libtiff (4.5.1) | Needs Triage | ||
| 23.2.1 | libtiff (4.3.0) | Needs Triage | ||
| 23.2 | libtiff (4.3.0) | Needs Triage | ||
| 23.1 | libtiff (4.3.0) | Needs Triage | ||
| 22.4 | libtiff (4.3.0) | Needs Triage | ||
| 22.3 | libtiff (4.3.0) | Needs Triage | ||
| 22.2 | libtiff (4.3.0) | Needs Triage | ||
| 22.1 | libtiff (4.0.8) | Needs Triage | ||
| 21.11.1 | libtiff (4.0.8) | Needs Triage | ||
| 21.11 | libtiff (4.0.8) | Needs Triage | ||
| 21.8.1 | libtiff (4.0.8) | Needs Triage | ||
| 21.8 | libtiff (4.0.8) | Needs Triage | ||
| 21.5.1 | libtiff (4.0.8) | Needs Triage | ||
| 21.5.0 | libtiff (4.0.8) | Needs Triage | ||
| 21.2.0 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.20 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.19.3667 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.18.3599 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.17 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.16.3445 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.15.3368 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.14.3263 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.13.3179 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.12.3054 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.11.3040 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.11.2990 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.10.2934 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.9.2878 | libtiff (4.0.8) | Needs Triage | ||
| 11.4.8.2822 | libtiff (4.0.8) | Needs Triage |
Severity score breakdown
Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
HIGH
Base Score
7.5
Base Severity
HIGH
Confidentiality Impact
NONE
Integrity Impact
NONE
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Version
3.1