Out-of-bounds write in LibTIFF - CVE-2023-52355
Published: February 23, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input within the TIFFRasterScanlineSize64() API. A remote attacker can pass a specially crafted TIFF file to the application, trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
Telemetry Dashboard
IBM Watson Machine Learning Accelerator
Liquidware
Citrix Workspace App
Business Automation Insights
Webex App VDI
IBM Cloud Pak for Security
IBM Cloud Pak for Business Automation
QRadar Suite
Anolis OS
Oracle Solaris
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
libtiff-doc
libtiff-tools
libtiff-static
libtiff-devel
libtiff
libtiff-opengl
How to mitigate CVE-2023-52355
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
IBM Watson Machine Learning Accelerator - update to 5.0.3
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF005, 24.0.1-IF004, 25.0.0
Business Automation Insights - update to 24.0.1.0.4
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libtiff-doc - addressed in versions 4.4.0-15.0.1, 4.5.1-6
libtiff-tools - addressed in versions 4.4.0-15.0.1, 4.5.1-6
libtiff-static - update to 4.4.0-15.0.1
libtiff-devel - addressed in versions 4.4.0-15.0.1, 4.5.1-6
libtiff - addressed in versions 4.4.0-15.0.1, 4.5.1-6
libtiff-opengl - update to 4.5.1-6
Oracle Solaris - addressed in versions 11.3 ESU 36.33, 11.4 SRU 68
External References
Related Security Bulletins
- Multiple vulnerabilities in LibTIFF
- Oracle Solaris update for thrid-party components
- Multiple vulnerabilities in Dell ThinOS
- Anolis OS update for libtiff
- Multiple vulnerabilities in IBM Cloud Pak for Security and IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Business Automation Insights
- Anolis OS update for libtiff
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data