Out-of-bounds write in LibTIFF - CVE-2023-52356

 

Out-of-bounds write in LibTIFF - CVE-2023-52356

Published: February 23, 2024 / Updated: March 3, 2025


Vulnerability identifier: #VU86755
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-52356
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input within the TIFFReadRGBATileExt() API. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

LibTIFF
Amazon Linux AMI
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
visionOS
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for x86_64
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
watchOS
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
macOS
Ubuntu
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
iPadOS
Apple iOS
tvOS
Fedora
Oracle Solaris
IBM Cloud Pak for Security
IBM Process Mining
IBM Cloud Pak for Business Automation
IBM Watson Machine Learning Accelerator
IBM Cloud Pak for Watson AIOps
Storage Resource Manager
Business Automation Insights
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libtiff-tools (Ubuntu package)
libtiff5 (Ubuntu package)
libtiff (Red Hat package)
libtiff-devel
tiff-debuginfo
tiff-debugsource
libtiff5
tiff
libtiff5-debuginfo
libtiff5-debuginfo-32bit
libtiff5-32bit
libtiff-devel-32bit
libtiff5-32bit-debuginfo
libtiff
libtiff-doc
libtiff-tools
libtiff-static
libtiff6 (Ubuntu package)
libtiff-opengl
libtiff6-64bit-debuginfo
libtiff-devel-64bit
libtiff6-64bit
libtiff6-32bit
libtiff6-32bit-debuginfo
libtiff-devel-docs
tiff-docs
libtiff6-debuginfo
libtiff6
SmartFabric Manager
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
QRadar Suite
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2023-52356

Install updates from vendor's website.

visionOS - update to 1.3
IBM Watson Machine Learning Accelerator - update to 5.0.3
watchOS - update to 10.6
macOS - addressed in versions 12.7.6 21H1320, 13.6.8 22G820, 14.6 23G80
iPadOS - addressed in versions 16.7.9 20H348, 17.6 21G80
Apple iOS - addressed in versions 16.7.9 20H348, 17.6 21G80
tvOS - update to 17.6
libtiff-tools (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 4.1.0+git191117-2ubuntu0.20.04.12, 4.3.0-6ubuntu0.8, 4.5.1+git230720-1ubuntu1.1
libtiff5 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 4.1.0+git191117-2ubuntu0.20.04.12, 4.3.0-6ubuntu0.8
SmartFabric Manager - update to 1.3.0
Migration Toolkit for Containers - update to 1.8.4
QRadar Suite - update to 1.10.26.0
IBM Process Mining - update to 1.15.0 IF003
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
libtiff (Red Hat package) - addressed in versions 4.0.9-32.el8_10, 4.4.0-13.el9_6.3, 4.6.0-6.el10_0.2, 4.6.0-6.el10_1.2
libtiff-devel - addressed in versions 4.0.9-44.77.1, 4.0.9-150000.45.38.1, 4.7.0-150600.3.8.1
tiff-debuginfo - addressed in versions 4.0.9-44.77.1, 4.0.9-150000.45.38.1, 4.7.0-150600.3.8.1
tiff-debugsource - addressed in versions 4.0.9-44.77.1, 4.0.9-150000.45.38.1, 4.7.0-150600.3.8.1
libtiff5 - addressed in versions 4.0.9-44.77.1, 4.0.9-150000.45.38.1
tiff - addressed in versions 4.0.9-44.77.1, 4.0.9-150000.45.38.1, 4.7.0-150600.3.8.1
libtiff5-debuginfo - addressed in versions 4.0.9-44.77.1, 4.0.9-150000.45.38.1
libtiff5-debuginfo-32bit - update to 4.0.9-44.77.1
libtiff5-32bit - addressed in versions 4.0.9-44.77.1, 4.0.9-150000.45.38.1
libtiff-devel-32bit - addressed in versions 4.0.9-150000.45.38.1, 4.7.0-150600.3.8.1
libtiff5-32bit-debuginfo - update to 4.0.9-150000.45.38.1
libtiff - update to 4.4.0-4
libtiff-doc - addressed in versions 4.4.0-12.0.2, 4.4.0-15.0.1, 4.5.1-6
libtiff-tools - addressed in versions 4.4.0-12.0.2, 4.4.0-15.0.1, 4.5.1-6
libtiff-static - addressed in versions 4.4.0-12.0.2, 4.4.0-15.0.1
libtiff-devel - addressed in versions 4.4.0-12.0.2, 4.4.0-15.0.1, 4.5.1-6
libtiff - addressed in versions 4.4.0-12.0.2, 4.4.0-15.0.1, 4.5.1-6
libtiff6 (Ubuntu package) - update to 4.5.1+git230720-1ubuntu1.1
libtiff-opengl - update to 4.5.1-6
libtiff - addressed in versions 4.6.0-5.fc40.1, 4.6.0-6.fc41, 4.6.0-6.fc42
IBM Cloud Pak for Watson AIOps - update to 4.7.0
libtiff6-64bit-debuginfo - update to 4.7.0-150600.3.8.1
libtiff-devel-64bit - update to 4.7.0-150600.3.8.1
libtiff6-64bit - update to 4.7.0-150600.3.8.1
libtiff6-32bit - update to 4.7.0-150600.3.8.1
libtiff6-32bit-debuginfo - update to 4.7.0-150600.3.8.1
libtiff-devel-docs - update to 4.7.0-150600.3.8.1
tiff-docs - update to 4.7.0-150600.3.8.1
libtiff6-debuginfo - update to 4.7.0-150600.3.8.1
libtiff6 - update to 4.7.0-150600.3.8.1
Storage Resource Manager - update to 4.10.0.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
Red Hat OpenShift Container Platform - addressed in versions 4.13.48, 4.15.28
Oracle Solaris - addressed in versions 11.3 ESU 36.33, 11.4 SRU 68
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001
Business Automation Insights - update to 24.0.0.0.1

External References

Related Security Bulletins