Vulnerability Description
Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libtiff | Libtiff | 4.0.7 |
Related Weaknesses (CWE)
References
- http://libtiff-release-v4-0-7.comRelease Notes
- http://tiffcp.comProduct
- https://gitlab.com/libtiff/libtiff/-/issues/538ExploitIssue TrackingVendor Advisory
- https://security.netapp.com/advisory/ntap-20230616-0003/
- http://libtiff-release-v4-0-7.comRelease Notes
- http://tiffcp.comProduct
- https://gitlab.com/libtiff/libtiff/-/issues/538ExploitIssue TrackingVendor Advisory
- https://security.netapp.com/advisory/ntap-20230616-0003/
FAQ
What is CVE-2023-30086?
CVE-2023-30086 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.
How severe is CVE-2023-30086?
CVE-2023-30086 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-30086?
Check the references section above for vendor advisories and patch information. Affected products include: Libtiff Libtiff.