Gentoo update for LibTIFF



Published: 2023-05-30
Risk High
Patch available YES
Number of vulnerabilities 11
CVE-ID CVE-2022-48281
CVE-2023-0795
CVE-2023-0796
CVE-2023-0797
CVE-2023-0798
CVE-2023-0799
CVE-2023-0800
CVE-2023-0801
CVE-2023-0802
CVE-2023-0803
CVE-2023-0804
CWE-ID CWE-122
CWE-125
CWE-787
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Gentoo Linux
Operating systems & Components / Operating system

media-libs/tiff
Operating systems & Components / Operating system package or component

Vendor Gentoo

Security Bulletin

This security bulletin contains information about 11 vulnerabilities.

1) Heap-based buffer overflow

EUVDB-ID: #VU71620

Risk: High

CVSSv3.1:

CVE-ID: CVE-2022-48281

CWE-ID:

Exploit availability:

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the processCropSelections() function in tools/tiffcrop.c in LibTIFF. A remote attacker can pass a specially crafted TIFF image to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update the affected packages.
media-libs/tiff to version: 4.5.0-r2

Vulnerable software versions

Gentoo Linux: All versions

media-libs/tiff: before 4.5.0-r2

Fixed software versions

CPE2.3 External links

http://security.gentoo.org/glsa/202305-31


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

2) Out-of-bounds read

EUVDB-ID: #VU72591

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2023-0795

CWE-ID:

Exploit availability:

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.

Mitigation

Update the affected packages.
media-libs/tiff to version: 4.5.0-r2

Vulnerable software versions

Gentoo Linux: All versions

media-libs/tiff: before 4.5.0-r2

Fixed software versions

CPE2.3 External links

http://security.gentoo.org/glsa/202305-31


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

3) Out-of-bounds read

EUVDB-ID: #VU72592

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2023-0796

CWE-ID:

Exploit availability:

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.

Mitigation

Update the affected packages.
media-libs/tiff to version: 4.5.0-r2

Vulnerable software versions

Gentoo Linux: All versions

media-libs/tiff: before 4.5.0-r2

Fixed software versions

CPE2.3 External links

http://security.gentoo.org/glsa/202305-31


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

4) Out-of-bounds read

EUVDB-ID: #VU72593

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2023-0797

CWE-ID:

Exploit availability:

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.

Mitigation

Update the affected packages.
media-libs/tiff to version: 4.5.0-r2

Vulnerable software versions

Gentoo Linux: All versions

media-libs/tiff: before 4.5.0-r2

Fixed software versions

CPE2.3 External links

http://security.gentoo.org/glsa/202305-31


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

5) Out-of-bounds read

EUVDB-ID: #VU72594

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2023-0798

CWE-ID:

Exploit availability:

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.

Mitigation

Update the affected packages.
media-libs/tiff to version: 4.5.0-r2

Vulnerable software versions

Gentoo Linux: All versions

media-libs/tiff: before 4.5.0-r2

Fixed software versions

CPE2.3 External links

http://security.gentoo.org/glsa/202305-31


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

6) Out-of-bounds read

EUVDB-ID: #VU72595

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2023-0799

CWE-ID:

Exploit availability:

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.

Mitigation

Update the affected packages.
media-libs/tiff to version: 4.5.0-r2

Vulnerable software versions

Gentoo Linux: All versions

media-libs/tiff: before 4.5.0-r2

Fixed software versions

CPE2.3 External links

http://security.gentoo.org/glsa/202305-31


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

7) Out-of-bounds read

EUVDB-ID: #VU72596

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2023-0800

CWE-ID:

Exploit availability:

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.

Mitigation

Update the affected packages.
media-libs/tiff to version: 4.5.0-r2

Vulnerable software versions

Gentoo Linux: All versions

media-libs/tiff: before 4.5.0-r2

Fixed software versions

CPE2.3 External links

http://security.gentoo.org/glsa/202305-31


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

8) Out-of-bounds read

EUVDB-ID: #VU72597

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2023-0801

CWE-ID:

Exploit availability:

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.

Mitigation

Update the affected packages.
media-libs/tiff to version: 4.5.0-r2

Vulnerable software versions

Gentoo Linux: All versions

media-libs/tiff: before 4.5.0-r2

Fixed software versions

CPE2.3 External links

http://security.gentoo.org/glsa/202305-31


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

9) Out-of-bounds read

EUVDB-ID: #VU72598

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2023-0802

CWE-ID:

Exploit availability:

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.

Mitigation

Update the affected packages.
media-libs/tiff to version: 4.5.0-r2

Vulnerable software versions

Gentoo Linux: All versions

media-libs/tiff: before 4.5.0-r2

Fixed software versions

CPE2.3 External links

http://security.gentoo.org/glsa/202305-31


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

10) Out-of-bounds write

EUVDB-ID: #VU72600

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2023-0803

CWE-ID:

Exploit availability:

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds write and perform a denial of service (DoS) attack.

Mitigation

Update the affected packages.
media-libs/tiff to version: 4.5.0-r2

Vulnerable software versions

Gentoo Linux: All versions

media-libs/tiff: before 4.5.0-r2

Fixed software versions

CPE2.3 External links

http://security.gentoo.org/glsa/202305-31


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?

11) Out-of-bounds write

EUVDB-ID: #VU72601

Risk: Medium

CVSSv3.1:

CVE-ID: CVE-2023-0804

CWE-ID:

Exploit availability:

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds write and perform a denial of service (DoS) attack.

Mitigation

Update the affected packages.
media-libs/tiff to version: 4.5.0-r2

Vulnerable software versions

Gentoo Linux: All versions

media-libs/tiff: before 4.5.0-r2

Fixed software versions

CPE2.3 External links

http://security.gentoo.org/glsa/202305-31


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?



###SIDEBAR###