Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 9: 2024-0077 Moderate: libtiff Integer Overflow DoS Threat

mageia
Calendar Grey March 20, 2024
Dist Mageia Esm H88
Mageia's LibPNG security patch resolves critical buffer overflow vulnerabilities, reducing chances of service disruption and unauthorized code execution.
LibTIFF is vulnerable to an integer overflow

Summary

LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. (CVE-2023-40745) A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow. (CVE-2023-41175)

References

- https://bugs.mageia.org/show_bug.cgi?id=32983

- https://lwn.net/Articles/965827/

- https://www.cve.org/CVERecord?id=CVE-2023-40745

- https://www.cve.org/CVERecord?id=CVE-2023-41175

Resolution

SRPMS

- 9/core/libtiff-4.5.1-1.2.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 20 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0077.html
Type: security
CVE: CVE-2023-40745, CVE-2023-41175

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here