Search CVE reports


Toggle filters

31 – 40 of 281 results


CVE-2023-3316

Low priority

Some fixes available 5 of 6

A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed Fixed Fixed
Show less packages

CVE-2023-26965

Low priority

Some fixes available 6 of 7

loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed Fixed Fixed
Show less packages

CVE-2023-25434

Low priority
Fixed

libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed Fixed Fixed
Show less packages

CVE-2023-30775

Medium priority
Fixed

A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed Fixed Fixed
Show less packages

CVE-2023-30774

Medium priority
Fixed

A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROFINKS values.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed Fixed Fixed
Show less packages

CVE-2023-2731

Low priority

Some fixes available 1 of 2

A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer...

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Not affected Not affected Not affected
Show less packages

CVE-2023-30086

Low priority
Fixed

Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed Fixed Fixed
Show less packages

CVE-2023-1916

Low priority

Some fixes available 7 of 9

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service...

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed Fixed Fixed Fixed
Show less packages

CVE-2022-4645

Medium priority
Fixed

LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed Fixed Fixed
Show less packages

CVE-2023-0804

Medium priority
Fixed

LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.

1 affected package

tiff

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tiff Fixed Fixed Fixed
Show less packages