VYPR
Unrated severityNVD Advisory· Published Apr 10, 2023· Updated Aug 2, 2024

CVE-2023-1916

CVE-2023-1916

Description

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

Affected products

1
  • Range: libtiff versions 4.x and newer are affected

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.