HomeDefectsLIN1023-3501
Fixed

LIN1023-3501 : Security Advisory - tiff - CVE-2023-52356

Created: Jan 26, 2024    Updated: Feb 7, 2024
Resolved Date: Feb 6, 2024
Found In Version: 10.23.30.1
Fix Version: 10.23.30.6
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.

CREATE(Triage):(User=admin) CVE-2023-52356 (https://nvd.nist.gov/vuln/detail/CVE-2023-52356)

CVEs