CVE-2023-2908
Libtiff: null pointer dereference in tif_dir.c
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A null pointer dereference issue was found in Libtiff's tif_dir.c file. This issue may allow an attacker to pass a crafted TIFF image file to the tiffcp utility which triggers a runtime error that causes undefined behavior. This will result in an application crash, eventually leading to a denial of service.
It was discovered that LibTIFF could be made to write out of bounds when processing certain malformed image files with the tiffcrop utility. If a user were tricked into opening a specially crafted image file, an attacker could possibly use this issue to cause tiffcrop to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. It was discovered that LibTIFF incorrectly handled certain image files. If a user were tricked into opening a specially crafted image file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 23.04.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-05-26 CVE Reserved
- 2023-06-30 CVE Published
- 2024-10-28 CVE Updated
- 2024-10-28 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-476: NULL Pointer Dereference
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://access.redhat.com/security/cve/CVE-2023-2908 | Third Party Advisory | |
https://bugzilla.redhat.com/show_bug.cgi?id=2218830 | Issue Tracking | |
https://lists.debian.org/debian-lts-announce/2023/07/msg00034.html | Third Party Advisory |
|
https://security.netapp.com/advisory/ntap-20230731-0004 | Third Party Advisory |
|
URL | Date | SRC |
---|---|---|
https://gitlab.com/libtiff/libtiff/-/merge_requests/479 | 2024-10-28 |
URL | Date | SRC |
---|---|---|
https://gitlab.com/libtiff/libtiff/-/commit/9bd48f0dbd64fb94dc2b5b05238fde0bfdd4ff3f | 2023-11-07 |
URL | Date | SRC |
---|