VDB
CISA-2023-52356
CISA-2023-52356
PUBLISHED
CVSS 7.5 HIGH
Reported by redhat · Published January 25, 2024
A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 0 | ||
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.0.9-32.el8_10 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:4.4.0-15.el9 |
| Red Hat | Red Hat AI Inference Server 3.2 | sha256:bddcf7ab6d576572b6d60822c313ffebcd9869e4fde93e32ac327821f93cf32b |
| Red Hat | Red Hat AI Inference Server 3.2 | sha256:7856bdb7ae0d643a7b9362c164d4d4fe3c0c7186f5fff73a7ae9835b3df52e57 |
| Red Hat | Red Hat AI Inference Server 3.2 | sha256:dce6b0ea03379bf06664a5200af8b5f5ae3fad13cdce6d21873843f22554800b |
| Red Hat | Red Hat AI Inference Server 3.2 | sha256:fa844e16d06e871f1a5dbc2fd5b3882d28112eee8d6bee601d94c96295c5e24f |
| Red Hat | Red Hat AI Inference Server 3.2 | sha256:53007894763e03f609c35c727cb738db3c2130b19fa0e1069c24240e0870fb7a |
| Red Hat | Red Hat Discovery 2 | sha256:310df392f638ef6eca1a26db024ae2cb617db5932f886d2acddc92fb7289e740 |
| Red Hat | Red Hat Enterprise Linux 10 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 8 | 0:4.0.9-32.el8_10, 0:4.0.9-32.el8_10, 0:4.0.9-32.el8_10 |
| Red Hat | Red Hat Discovery 2 | *, sha256:310df392f638ef6eca1a26db024ae2cb617db5932f886d2acddc92fb7289e740, sha256:310df392f638ef6eca1a26db024ae2cb617db5932f886d2acddc92fb7289e740 |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat AI Inference Server 3.2 | sha256:fa844e16d06e871f1a5dbc2fd5b3882d28112eee8d6bee601d94c96295c5e24f, sha256:dcb9d1cd005c40b6db6f893e56419e383b9dcc0d38315605cb1457e2af5354f7, sha256:bddcf7ab6d576572b6d60822c313ffebcd9869e4fde93e32ac327821f93cf32b |
| Red Hat | Red Hat Enterprise Linux 10 |
…and 7 more
Timeline
- Jan 25, 2024 CVE Published
- Feb 27, 2026 CVE Updated
- Mar 27, 2026 Distribution Patch
- Mar 27, 2026 Distribution Patch
- Mar 27, 2026 Distribution Patch
- Mar 27, 2026 Distribution Patch
- Mar 27, 2026 Distribution Patch
- Mar 27, 2026 Distribution Patch
- Mar 27, 2026 Distribution Patch
- Mar 27, 2026 Distribution Patch
- Mar 27, 2026 Distribution Patch
- Mar 27, 2026 Security Advisory
References
- RHSA-2024:5079 vendor-advisoryx_refsource_REDHAT
- RHSA-2025:20801 vendor-advisoryx_refsource_REDHAT
- RHSA-2025:21994 vendor-advisoryx_refsource_REDHAT
- RHSA-2025:23078 vendor-advisoryx_refsource_REDHAT
- RHSA-2025:23079 vendor-advisoryx_refsource_REDHAT
- RHSA-2025:23080 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:3461 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:3462 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2251344 issue-trackingx_refsource_REDHAT
- RHSA-2026:5958 vendor-advisory
- https://lists.debian.org/debian-lts-announce/2024/03/msg00011.html url
- https://support.apple.com/kb/HT214119 url
- https://support.apple.com/kb/HT214123 url
- https://support.apple.com/kb/HT214122 url
- https://support.apple.com/kb/HT214117 url
- https://support.apple.com/kb/HT214118 url
- https://support.apple.com/kb/HT214116 url
…and 11 more