7.5
CVE-2023-52355
- EPSS 1.83%
- Veröffentlicht 25.01.2024 20:15:38
- Zuletzt bearbeitet 02.10.2026 03:16:35
- Erkennungen
Libtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.83% | 0.767 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| RedHat | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://bugzilla.redhat.com/show_bug.cgi?id=2251326
https://gitlab.com/libtiff/libtiff/-/issues/621
https://access.redhat.com/errata/RHSA-2026:3461
https://access.redhat.com/errata/RHSA-2026:3462
https://access.redhat.com/errata/RHSA-2025:23078
https://access.redhat.com/errata/RHSA-2025:23079
https://access.redhat.com/errata/RHSA-2025:23080
https://access.redhat.com/errata/RHSA-2026:41892
https://access.redhat.com/errata/RHSA-2025:20801
https://access.redhat.com/errata/RHSA-2025:21994
https://access.redhat.com/security/cve/CVE-2023-52355
https://access.redhat.com/errata/RHSA-2026:43537
https://access.redhat.com/errata/RHSA-2026:49671
https://access.redhat.com/errata/RHSA-2026:73909
https://access.redhat.com/errata/RHSA-2026:73959
https://access.redhat.com/errata/RHSA-2026:73960
https://access.redhat.com/errata/RHSA-2026:73961
https://access.redhat.com/errata/RHSA-2026:73962
https://access.redhat.com/errata/RHSA-2026:74458
https://access.redhat.com/errata/RHSA-2026:74459
https://access.redhat.com/errata/RHSA-2026:74460
https://access.redhat.com/errata/RHSA-2026:74461
https://access.redhat.com/errata/RHSA-2026:74462
https://access.redhat.com/errata/RHSA-2026:74463
https://access.redhat.com/errata/RHSA-2026:74674