CVE-2023-2731

A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

03 Jul 2023, 16:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20230703-0009/ -

Information

Published : 2023-05-17 22:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-2731

Mitre link : CVE-2023-2731

CVE.ORG link : CVE-2023-2731


JSON object : View

Products Affected

libtiff

  • libtiff

redhat

  • enterprise_linux

fedoraproject

  • fedora
CWE
CWE-476

NULL Pointer Dereference