Back to bug 2207635

Who When What Removed Added
TEJ RATHI 2023-05-16 12:02:36 UTC CC adudiak, bdettelb, caswilli, dkuc, drieden, fjansen, hkataria, ikanias, jary, jburrell, jkoehler, jwong, kaycoth, kshier, micjohns, mmuzila, nforro, rh-spice-bugs, rravi, sthirugn, tohughes
TEJ RATHI 2023-05-16 12:10:41 UTC Depends On 2207638, 2207640, 2207639, 2207637
TEJ RATHI 2023-05-16 12:14:02 UTC Depends On 2207643
TEJ RATHI 2023-05-16 13:35:13 UTC Blocks 2203211
Paige Jung 2023-05-16 14:00:25 UTC CC adudiak, jwong
CC jkoehler
Doc Text A null pointer dereference issue was discovered in Libtiff's LZWDecode() function of libtiff/tif_lzw.c file. A local attacker could exploit this vulnerability by crafting specific input data that would cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service. A null pointer dereference issue was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This issue could allow a local attacker to craft specific input data that would cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
RaTasha Tillery-Smith 2023-05-16 14:01:35 UTC Doc Text A null pointer dereference issue was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This issue could allow a local attacker to craft specific input data that would cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service. A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
TEJ RATHI 2023-05-17 12:41:10 UTC Fixed In Version libtiff 4.5.0
Red Hat Bugzilla 2023-07-07 08:32:30 UTC Assignee security-response-team nobody

Back to bug 2207635