Integer overflow in LibTIFF - CVE-2023-41175
Published: October 8, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in raw2tiff.c A remote attacker can create a specially crafted TIFF file, trick the victim into opening it with the affected software, trigger an integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Data Lakehouse
Red Hat OpenShift Dev Spaces
IBM Watson Discovery for IBM Cloud Pak for Data
Red Hat Migration Toolkit for Applications
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Datacap
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
Red Hat OpenShift Container Platform
OpenShift API for Data Protection (OADP)
libtiff
tiff (Debian package)
libtiff (Red Hat package)
libtiff-doc
libtiff-tools
libtiff-static
libtiff-devel
libtiff-opengl
How to mitigate CVE-2023-41175
Data Lakehouse - update to 1.1.0.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
OpenShift API for Data Protection (OADP) - update to 1.3.2
Red Hat OpenShift Dev Spaces - update to 3.16.0
libtiff - addressed in versions 4.0.3-35.49, 4.4.0-4
tiff (Debian package) - addressed in versions 4.2.0-1+deb11u5, 4.5.0-6+deb12u1
libtiff (Red Hat package) - update to 4.4.0-12.el9
libtiff-doc - addressed in versions 4.4.0-12.0.1, 4.5.1-2
libtiff-tools - addressed in versions 4.4.0-12.0.1, 4.5.1-2
libtiff-static - update to 4.4.0-12.0.1
libtiff-devel - addressed in versions 4.4.0-12.0.1, 4.5.1-2
libtiff - addressed in versions 4.4.0-12.0.1, 4.5.1-2
libtiff-opengl - update to 4.5.1-2
Red Hat OpenShift Container Platform - addressed in versions 4.16.15, 4.17.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.0.0
Red Hat Migration Toolkit for Applications - update to 6.2.3
Datacap - update to 9.1.9.0.4
External References
Related Security Bulletins
- Remote code execution in libtiff
- Amazon Linux AMI update for libtiff
- Debian update for tiff
- Multiple vulnerabilities in IBM Datacap
- Red Hat Enterprise Linux 9 update for libtiff
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 6.2
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Amazon Linux AMI update for libtiff
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Integer overflow in IBM Watson Discovery
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Amazon Linux AMI update for libtiff
- Anolis OS update for libtiff
- Anolis OS update for libtiff