Risk | High |
Patch available | YES |
Number of vulnerabilities | 11 |
CVE-ID | CVE-2022-48281 CVE-2023-0795 CVE-2023-0796 CVE-2023-0797 CVE-2023-0798 CVE-2023-0799 CVE-2023-0800 CVE-2023-0801 CVE-2023-0802 CVE-2023-0803 CVE-2023-0804 |
CWE-ID | CWE-122 CWE-125 CWE-787 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
Gentoo Linux Operating systems & Components / Operating system media-libs/tiff Operating systems & Components / Operating system package or component |
Vendor | Gentoo |
Security Bulletin
This security bulletin contains information about 11 vulnerabilities.
EUVDB-ID: #VU71620
Risk: High
CVSSv3.1:
CVE-ID: CVE-2022-48281
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the processCropSelections() function in tools/tiffcrop.c in LibTIFF. A remote attacker can pass a specially crafted TIFF image to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationUpdate the affected packages.
media-libs/tiff to version: 4.5.0-r2
Gentoo Linux: All versions
media-libs/tiff: before 4.5.0-r2
Fixed software versionsCPE2.3 External links
http://security.gentoo.org/glsa/202305-31
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU72591
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-0795
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.
Update the affected packages.
media-libs/tiff to version: 4.5.0-r2
Gentoo Linux: All versions
media-libs/tiff: before 4.5.0-r2
Fixed software versionsCPE2.3 External links
http://security.gentoo.org/glsa/202305-31
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU72592
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-0796
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack. MitigationUpdate the affected packages.
media-libs/tiff to version: 4.5.0-r2
Gentoo Linux: All versions
media-libs/tiff: before 4.5.0-r2
Fixed software versionsCPE2.3 External links
http://security.gentoo.org/glsa/202305-31
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU72593
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-0797
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack. MitigationUpdate the affected packages.
media-libs/tiff to version: 4.5.0-r2
Gentoo Linux: All versions
media-libs/tiff: before 4.5.0-r2
Fixed software versionsCPE2.3 External links
http://security.gentoo.org/glsa/202305-31
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU72594
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-0798
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack. MitigationUpdate the affected packages.
media-libs/tiff to version: 4.5.0-r2
Gentoo Linux: All versions
media-libs/tiff: before 4.5.0-r2
Fixed software versionsCPE2.3 External links
http://security.gentoo.org/glsa/202305-31
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU72595
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-0799
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack. MitigationUpdate the affected packages.
media-libs/tiff to version: 4.5.0-r2
Gentoo Linux: All versions
media-libs/tiff: before 4.5.0-r2
Fixed software versionsCPE2.3 External links
http://security.gentoo.org/glsa/202305-31
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU72596
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-0800
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack. MitigationUpdate the affected packages.
media-libs/tiff to version: 4.5.0-r2
Gentoo Linux: All versions
media-libs/tiff: before 4.5.0-r2
Fixed software versionsCPE2.3 External links
http://security.gentoo.org/glsa/202305-31
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU72597
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-0801
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack. MitigationUpdate the affected packages.
media-libs/tiff to version: 4.5.0-r2
Gentoo Linux: All versions
media-libs/tiff: before 4.5.0-r2
Fixed software versionsCPE2.3 External links
http://security.gentoo.org/glsa/202305-31
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU72598
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-0802
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack. MitigationUpdate the affected packages.
media-libs/tiff to version: 4.5.0-r2
Gentoo Linux: All versions
media-libs/tiff: before 4.5.0-r2
Fixed software versionsCPE2.3 External links
http://security.gentoo.org/glsa/202305-31
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU72600
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-0803
CWE-ID:
Exploit availability:
Description The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the tiffcrop() function in tools/tiffcrop.c. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds write and perform a denial of service (DoS) attack.
Update the affected packages.
media-libs/tiff to version: 4.5.0-r2
Gentoo Linux: All versions
media-libs/tiff: before 4.5.0-r2
Fixed software versionsCPE2.3 External links
http://security.gentoo.org/glsa/202305-31
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU72601
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2023-0804
CWE-ID:
Exploit availability:
Description The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
Update the affected packages.
media-libs/tiff to version: 4.5.0-r2
Gentoo Linux: All versions
media-libs/tiff: before 4.5.0-r2
Fixed software versionsCPE2.3 External links
http://security.gentoo.org/glsa/202305-31
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?