CVE-2023-6228

EUVD-2023-58475
An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 LOW
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
redhatCNA
3.3 LOW
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
Affected Products (NVD)
VendorProductVersion
libtifflibtiff
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tiff
bookworm
unimportant
bookworm (security)
unimportant
bullseye
unimportant
bullseye (security)
unimportant
sid
unimportant
trixie
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libgeotiff
bionic
ignored
focal
needs-triage
jammy
needs-triage
lunar
ignored
mantic
ignored
noble
needs-triage
oracular
needs-triage
trusty
ignored
xenial
ignored
libtk-img
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
lunar
ignored
mantic
ignored
noble
needs-triage
oracular
needs-triage
trusty
ignored
xenial
needs-triage
povray
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
lunar
ignored
mantic
ignored
noble
needs-triage
oracular
needs-triage
trusty
ignored
xenial
needs-triage
tiff
bionic
Fixed 4.0.9-5ubuntu0.10+esm5
released
focal
Fixed 4.1.0+git191117-2ubuntu0.20.04.12
released
jammy
Fixed 4.3.0-6ubuntu0.8
released
lunar
ignored
mantic
Fixed 4.5.1+git230720-1ubuntu1.1
released
noble
Fixed 4.5.1+git230720-4ubuntu1
released
oracular
Fixed 4.5.1+git230720-4ubuntu1
released
trusty
Fixed 4.0.3-7ubuntu0.11+esm12
released
xenial
Fixed 4.0.6-1ubuntu0.8+esm15
released