A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libtiff-toolsUpgrade libtiff-develUpgrade libtiff | Nov 16, 2023 | May 17, 2023 |
| Amazon_linux_2023 | — | Upgrade libtiff-debuginfoUpgrade libtiff-develUpgrade libtiff-toolsUpgrade libtiffUpgrade libtiff-tools-debuginfoUpgrade libtiff-staticUpgrade libtiff-debugsource | Feb 17, 2025 | Apr 22, 2023 |
| Centos_linux | — | Upgrade libtiff-develUpgrade libtiff-debuginfoUpgrade libtiff-debugsourceUpgrade libtiffUpgrade libtiff-tools-debuginfo | Nov 8, 2023 | May 17, 2023 |
| Debian | — | Upgrade tiff | Jul 30, 2024 | May 17, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade libtiff | Jan 10, 2024 | May 17, 2023 |
| Oracle_linux | — | Upgrade libtiff-toolsUpgrade libtiffUpgrade libtiff-devel | Nov 16, 2023 | Apr 22, 2023 |
| Redhat_linux | — | Upgrade libtiffUpgrade libtiff-debuginfoUpgrade libtiff-tools-debuginfoUpgrade libtiff-debugsourceUpgrade libtiff-toolsUpgrade libtiff-devel | Nov 8, 2023 | May 17, 2023 |
| Suse | — | Upgrade tiffUpgrade libtiff5Upgrade libtiff-devel-32bitUpgrade libtiff5-32bitUpgrade libtiff-devel | Dec 13, 2023 | May 17, 2023 |
| Ubuntu | — | Upgrade libtiff6Upgrade libtiff5 (Ubuntu Pro)Upgrade libtiff-tools (Ubuntu Pro)Upgrade libtiff5Upgrade libtiff-tools | Aug 16, 2023 | May 17, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 17, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub