DescriptionDhananjay Arunesh
2023-07-24 07:12:26 UTC
Multiple potential integer overflow in tiffcp.c in libtiff <= 4.5.1 can allow remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image which triggers a heap-based buffer overflow.
Comment 3Salvatore Bonaccorso
2023-07-30 22:02:16 UTC
Comment 4Dhananjay Arunesh
2023-08-02 09:28:19 UTC
In reply to comment #3:
> This CVE is referenced at https://gitlab.com/libtiff/libtiff/-/issues/592
> (but it looks that this RHBZ entry is swapped with actually CVE-2023-38288).
Hi, These CVEs are assigned by us (Red Hat CNA), CVEs attached to the bugs are from the final vulnerabilities report sent by the reporter. I am discussing about this issue with the reporter to rectify from his end.
Comment 5Salvatore Bonaccorso
2023-08-13 11:45:38 UTC