Buffer overflow in LibTIFF - CVE-2023-3618

 

Buffer overflow in LibTIFF - CVE-2023-3618

Published: August 10, 2023


Vulnerability identifier: #VU79327
CSH Severity: Medium
CVSS v4 BT: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-3618
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to buffer overflow in the Fax3Encode() function in libtiff/tif_fax3.c. A remote unauthenticated attacker can trick the victim into opening a specially crafted file and perform a denial of service attack.


Affected software

LibTIFF
Amazon Linux AMI
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
macOS
Ubuntu
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
openEuler
SQL Sentry
libtiff-tools (Ubuntu package)
libtiff5 (Ubuntu package)
tiff
libtiff-devel
libtiff5-debuginfo
libtiff5
libtiff5-debuginfo-32bit
libtiff5-32bit
tiff-debugsource
tiff-debuginfo
libtiff-devel-32bit
libtiff5-32bit-debuginfo
libtiff-debuginfo
libtiff-debugsource
libtiff
libtiff-help
libtiff (Red Hat package)
libtiff-static
libtiff-tools
libtiff-doc
libtiff6 (Ubuntu package)
OpenShift API for Data Protection (OADP)
VMware Tanzu Operations Manager
Isolation Segment
VMware Tanzu Application Service for VMs
Red Hat OpenShift Dev Spaces
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
Red Hat OpenShift Container Platform
Datacap

How to mitigate CVE-2023-3618

Install updates from vendor's website.

LibTIFF - update to 4.5.1
macOS - addressed in versions 12.7.2 21G1974, 13.6.3 22G436, 14.2 23C64
SQL Sentry - update to 2024.2
libtiff-tools (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 4.1.0+git191117-2ubuntu0.20.04.9, 4.3.0-6ubuntu0.5, 4.5.0-5ubuntu1.1
libtiff5 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 4.1.0+git191117-2ubuntu0.20.04.9, 4.3.0-6ubuntu0.5
OpenShift API for Data Protection (OADP) - update to 1.3.2
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39
Isolation Segment - addressed in versions 2.11.38, 2.13.23, 3.0.16, 4.0.8
VMware Tanzu Application Service for VMs - addressed in versions 2.11.44, 2.13.26, 3.0.16, 4.0.8
Red Hat OpenShift Dev Spaces - update to 3.16.0
tiff - addressed in versions 4.0.9-44.71.1, 4.0.9-150000.45.32.1
libtiff-devel - addressed in versions 4.0.9-44.71.1, 4.0.9-150000.45.32.1
libtiff5-debuginfo - addressed in versions 4.0.9-44.71.1, 4.0.9-150000.45.32.1
libtiff5 - addressed in versions 4.0.9-44.71.1, 4.0.9-150000.45.32.1
libtiff5-debuginfo-32bit - update to 4.0.9-44.71.1
libtiff5-32bit - addressed in versions 4.0.9-44.71.1, 4.0.9-150000.45.32.1
tiff-debugsource - addressed in versions 4.0.9-44.71.1, 4.0.9-150000.45.32.1
tiff-debuginfo - addressed in versions 4.0.9-44.71.1, 4.0.9-150000.45.32.1
libtiff-devel-32bit - update to 4.0.9-150000.45.32.1
libtiff5-32bit-debuginfo - update to 4.0.9-150000.45.32.1
libtiff-debuginfo - update to 4.3.0-17
libtiff-debugsource - update to 4.3.0-17
libtiff-devel - update to 4.3.0-17
libtiff - update to 4.3.0-17
libtiff-help - update to 4.3.0-17
libtiff - update to 4.4.0-4
libtiff (Red Hat package) - update to 4.4.0-12.el9
libtiff - update to 4.4.0-12.0.1
libtiff-devel - update to 4.4.0-12.0.1
libtiff-static - update to 4.4.0-12.0.1
libtiff-tools - update to 4.4.0-12.0.1
libtiff-doc - update to 4.4.0-12.0.1
libtiff6 (Ubuntu package) - update to 4.5.0-5ubuntu1.1
Red Hat OpenShift Container Platform - addressed in versions 4.16.15, 4.17.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.0.0
App Connect Enterprise Certified Container - addressed in versions 5.0.9, 9.1.0
Red Hat Migration Toolkit for Applications - update to 6.2.3
Datacap - update to 9.1.9.0.4

External References

Related Security Bulletins