Buffer overflow in LibTIFF - CVE-2023-25435
Published: August 10, 2023
Vulnerability details
The vulnerability allows a local attacker to perform a denial of service attack.
The vulnerability exists due to buffer overflow in the extractContigSamplesShifted8bits() at /libtiff/tools/tiffcrop.c:3753. A local unauthenticated attacker can trick the victim into opening a specially crafted file and perform a denial of service attack.
Affected software
Amazon Linux AMI
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
Data Lakehouse
App Connect Enterprise Certified Container
SmartFabric Manager
libtiff
libtiff-devel
libtiff-devel-64bit
libtiff6-64bit
libtiff6-64bit-debuginfo
libtiff6-32bit
libtiff-devel-32bit
libtiff6-32bit-debuginfo
libtiff-devel-docs
tiff-docs
libtiff6-debuginfo
libtiff6
tiff-debuginfo
tiff
tiff-debugsource
Datacap
How to mitigate CVE-2023-25435
Data Lakehouse - update to 1.1.0.0
SmartFabric Manager - update to 1.3.0
libtiff - update to 4.4.0-4
libtiff-devel - update to 4.7.0-150600.3.8.1
libtiff-devel-64bit - update to 4.7.0-150600.3.8.1
libtiff6-64bit - update to 4.7.0-150600.3.8.1
libtiff6-64bit-debuginfo - update to 4.7.0-150600.3.8.1
libtiff6-32bit - update to 4.7.0-150600.3.8.1
libtiff-devel-32bit - update to 4.7.0-150600.3.8.1
libtiff6-32bit-debuginfo - update to 4.7.0-150600.3.8.1
libtiff-devel-docs - update to 4.7.0-150600.3.8.1
tiff-docs - update to 4.7.0-150600.3.8.1
libtiff6-debuginfo - update to 4.7.0-150600.3.8.1
libtiff6 - update to 4.7.0-150600.3.8.1
tiff-debuginfo - update to 4.7.0-150600.3.8.1
tiff - update to 4.7.0-150600.3.8.1
tiff-debugsource - update to 4.7.0-150600.3.8.1
App Connect Enterprise Certified Container - addressed in versions 5.0.9, 9.1.0
Datacap - update to 9.1.9.0.4