Out-of-Bounds Read Vulnerability in libtiff's tiffcrop Tool
CVE-2023-1916

6.1MEDIUM

Key Information:

Vendor

Libtiff

Status
Vendor
CVE Published:
10 April 2023

What is CVE-2023-1916?

A flaw exists in the tiffcrop program, part of the libtiff package, that allows for an out-of-bounds read. This vulnerability occurs in the extractImageSection function within tools/tiffcrop.c when processing specially crafted TIFF files. Exploiting this flaw can result in a denial of service and expose limited information, making it a significant concern for users of libtiff version 4.x.

Affected Version(s)

libtiff libtiff versions 4.x and newer are affected

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-1916 : Out-of-Bounds Read Vulnerability in libtiff's tiffcrop Tool