Out-of-Bounds Read Vulnerability in LibTIFF 4.4.0 by LibTIFF
CVE-2023-0798
5.5MEDIUM
What is CVE-2023-0798?
LibTIFF 4.4.0 is affected by an out-of-bounds read vulnerability in the tiffcrop tool, specifically in the file tools/tiffcrop.c at line 3400. This vulnerability allows attackers to engineer a crafted TIFF file, leading to potential denial-of-service conditions. Users compiling LibTIFF from source can apply the necessary fix, which is detailed in commit afaabc3e.
Affected Version(s)
libtiff <=4.4.0
