Buffer Overflow Vulnerability in Libtiff Affects Local Attackers
CVE-2023-30086

5.5MEDIUM

Key Information:

Vendor

Libtiff

Status
Vendor
CVE Published:
9 May 2023

What is CVE-2023-30086?

A buffer overflow vulnerability has been identified in Libtiff version 4.0.7, specifically within the tiffcp function found in tiffcp.c. This security flaw can be exploited by a local attacker to execute a denial of service, potentially interrupting normal operations. Users of Libtiff are advised to review their systems for this specific version to mitigate any risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.