Heap-based buffer overflow in LibTIFF - CVE-2023-6228
Published: February 23, 2024 / Updated: March 3, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the cpStripToTile() function in libtiff/tools/tiffcp.c. A remote attacker can pass a specially crafted TIFF image to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
IBM Cloud Pak for Security
IBM Process Mining
Red Hat OpenShift Dev Spaces
IBM Watson Discovery for IBM Cloud Pak for Data
Red Hat Migration Toolkit for Applications
IBM Cloud Pak for Business Automation
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Ubuntu
openEuler
Fedora
libtiff-tools (Ubuntu package)
libtiff5 (Ubuntu package)
libtiff (Red Hat package)
libtiff-devel
libtiff-help
libtiff-debugsource
libtiff-debuginfo
libtiff
libtiff-doc
libtiff-tools
libtiff-static
libtiff6 (Ubuntu package)
libtiff-opengl
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
QRadar Suite
Business Automation Insights
How to mitigate CVE-2023-6228
libtiff5 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 4.1.0+git191117-2ubuntu0.20.04.12, 4.3.0-6ubuntu0.8
OpenShift API for Data Protection (OADP) - update to 1.3.2
Migration Toolkit for Containers - update to 1.8.4
QRadar Suite - update to 1.10.26.0
IBM Process Mining - update to 1.15.0 IF003
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
Red Hat OpenShift Dev Spaces - update to 3.16.0
libtiff (Red Hat package) - addressed in versions 4.0.9-32.el8_10, 4.4.0-12.el9
libtiff-devel - update to 4.3.0-20
libtiff-help - update to 4.3.0-20
libtiff-debugsource - update to 4.3.0-20
libtiff-debuginfo - update to 4.3.0-20
libtiff - update to 4.3.0-20
libtiff-doc - addressed in versions 4.4.0-12.0.1, 4.5.1-5
libtiff-tools - addressed in versions 4.4.0-12.0.1, 4.5.1-5
libtiff-static - update to 4.4.0-12.0.1
libtiff-devel - addressed in versions 4.4.0-12.0.1, 4.5.1-5
libtiff - addressed in versions 4.4.0-12.0.1, 4.5.1-5
libtiff6 (Ubuntu package) - update to 4.5.1+git230720-1ubuntu1.1
libtiff-opengl - update to 4.5.1-5
libtiff - addressed in versions 4.6.0-5.fc40.1, 4.6.0-6.fc41, 4.6.0-6.fc42
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.48, 4.15.28, 4.16.15, 4.17.0
Red Hat Migration Toolkit for Applications - update to 6.2.3
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001
Business Automation Insights - update to 24.0.0.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in LibTIFF
- Ubuntu update for tiff
- Ubuntu update for tiff
- openEuler update for libtiff
- Red Hat Enterprise Linux 9 update for libtiff
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 6.2
- Heap-based buffer overflow in IBM Watson Discovery for IBM Cloud Pak for Data
- Red Hat Enterprise Linux 8 update for libtiff
- Fedora 42 update for libtiff
- Fedora 41 update for libtiff
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Process Mining
- Fedora 40 update for libtiff
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Anolis OS update for libtiff
- Anolis OS update for libtiff
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management