Heap Buffer Overflow in LibTIFF Library Affects Multiple Products
CVE-2023-30775

5.5MEDIUM

Key Information:

Vendor

Libtiff

Status
Vendor
CVE Published:
19 May 2023

What is CVE-2023-30775?

A security flaw has been identified in the libtiff library, specifically within the 'extractContigSamples32bits' function in the 'tiffcrop.c' file. This vulnerability allows for a heap buffer overflow, potentially leading to unauthorized access or disruption of service. Users of affected versions are strongly advised to update their software to safeguard against potential exploitation.

Affected Version(s)

libtiff 4.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.