Back to search
CVE-2023-2731
Published: May 17, 2023
Modified: Jan 22, 2025
PUBLISHED
Description
A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
| Vendor | Product | Versions |
|---|---|---|
n/a | libtiff | affected Fixed in libtiff v4.5.0 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now