CVE-2023-40745

NameCVE-2023-40745
Descriptionlibtiff: integer overflow in tiffcp.c
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3513-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tiff (PTS)buster4.1.0+git191117-2~deb10u4vulnerable
buster (security)4.1.0+git191117-2~deb10u8fixed
bullseye (security), bullseye4.2.0-1+deb11u4vulnerable
bookworm4.5.0-6vulnerable
sid, trixie4.5.1+git230720-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tiffsourcebuster4.1.0+git191117-2~deb10u8DLA-3513-1
tiffsource(unstable)4.5.1+git230720-1

Notes

https://gitlab.com/libtiff/libtiff/-/commit/4fc16f649fa2875d5c388cf2edc295510a247ee5
https://gitlab.com/libtiff/libtiff/-/issues/591
https://bugzilla.redhat.com/show_bug.cgi?id=2235265

Search for package or bug name: Reporting problems