CVE-2019-14973

Description

_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application crash.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.965

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Tag Image File Format (TIFF) library (USN-4158-1) libtiff5_4.0.6-1ubuntu0.7_i386.debLinux
Tag Image File Format (TIFF) library (USN-4158-1) libtiff5_4.0.6-1ubuntu0.7_amd64.debLinux
Tag Image File Format (TIFF) library (USN-4158-1) libtiff5_4.0.9-5ubuntu0.3_i386.debLinux
Tag Image File Format (TIFF) library (USN-4158-1) libtiff5_4.0.9-5ubuntu0.3_amd64.debLinux
Tag Image File Format (TIFF) library (USN-4158-1) libtiff5_4.0.10-4ubuntu0.1_i386.debLinux
Tag Image File Format (TIFF) library (USN-4158-1) libtiff5_4.0.10-4ubuntu0.1_amd64.debLinux
Tag Image File Format (TIFF) library (USN-4158-1) libtiff-tools_4.0.6-1ubuntu0.7_i386.debLinux
Tag Image File Format (TIFF) library (USN-4158-1) libtiff-tools_4.0.6-1ubuntu0.7_amd64.debLinux
Tag Image File Format (TIFF) library (USN-4158-1) libtiff-tools_4.0.9-5ubuntu0.3_i386.debLinux
Tag Image File Format (TIFF) library (USN-4158-1) libtiff-tools_4.0.9-5ubuntu0.3_amd64.debLinux
Tag Image File Format (TIFF) library (USN-4158-1) libtiff-tools_4.0.10-4ubuntu0.1_i386.debLinux
Tag Image File Format (TIFF) library (USN-4158-1) libtiff-tools_4.0.10-4ubuntu0.1_amd64.debLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Server 12-SP4 ) libtiff5-4.0.9-44.42.1.x86_64.rpmLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Server 12-SP4 ) libtiff5-32bit-4.0.9-44.42.1.x86_64.rpmLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Server 12-SP4 ) libtiff5-debuginfo-4.0.9-44.42.1.x86_64.rpmLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Server 12-SP4 ) libtiff5-debuginfo-32bit-4.0.9-44.42.1.x86_64.rpmLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Desktop 12-SP4 ) libtiff5-4.0.9-44.42.1.x86_64_SP4.rpmLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Desktop 12-SP4 ) libtiff5-32bit-4.0.9-44.42.1.x86_64_SP4.rpmLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Server 12-SP4 ) tiff-4.0.9-44.42.1.x86_64.rpmLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Desktop 12-SP4 ) libtiff5-debuginfo-4.0.9-44.42.1.x86_64_SP4.rpmLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Desktop 12-SP4 ) libtiff5-debuginfo-32bit-4.0.9-44.42.1.x86_64_SP4.rpmLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Desktop 12-SP4 ) tiff-debuginfo-4.0.9-44.42.1.x86_64.rpmLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Server 12-SP4 ) tiff-debuginfo-4.0.9-44.42.1.x86_64_SP4.rpmLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Desktop 12-SP4 ) tiff-debugsource-4.0.9-44.42.1.x86_64.rpmLinux
SUSE-SU-2019:3058-1(SUSE Linux Enterprise Server 12-SP4 ) tiff-debugsource-4.0.9-44.42.1.x86_64_SP4.rpmLinux
(RHSA-2020:1688) libtiff security update libtiff-4.0.9-17.el8.i686.rpmLinux
(RHSA-2020:1688) libtiff security update libtiff-4.0.9-17.el8.x86_64.rpmLinux
(RHSA-2020:1688) libtiff security update libtiff-debugsource-4.0.9-17.el8.i686.rpmLinux
(RHSA-2020:1688) libtiff security update libtiff-debugsource-4.0.9-17.el8.x86_64.rpmLinux
(RHSA-2020:1688) libtiff security update libtiff-devel-4.0.9-17.el8.i686.rpmLinux
(RHSA-2020:1688) libtiff security update libtiff-devel-4.0.9-17.el8.x86_64.rpmLinux
(RHSA-2020:3902) libtiff security update libtiff-4.0.3-35.el7.i686.rpmLinux
(RHSA-2020:3902) libtiff security update libtiff-4.0.3-35.el7.x86_64.rpmLinux
(RHSA-2020:3902) libtiff security update libtiff-devel-4.0.3-35.el7.i686.rpmLinux
(RHSA-2020:3902) libtiff security update libtiff-devel-4.0.3-35.el7.x86_64.rpmLinux
(RHSA-2020:3902) libtiff security update libtiff-static-4.0.3-35.el7.i686.rpmLinux
(RHSA-2020:3902) libtiff security update libtiff-static-4.0.3-35.el7.x86_64.rpmLinux
(RHSA-2020:3902) libtiff security update libtiff-tools-4.0.3-35.el7.x86_64.rpmLinux
(CESA-2020:1688) libtiff security update libtiff-4.0.9-17.el8.i686.rpmLinux
(CESA-2020:1688) libtiff security update libtiff-4.0.9-17.el8.x86_64.rpmLinux
(CESA-2020:1688) libtiff security update libtiff-devel-4.0.9-17.el8.i686.rpmLinux
(CESA-2020:1688) libtiff security update libtiff-devel-4.0.9-17.el8.x86_64.rpmLinux
(CESA-2020:3902) libtiff security update libtiff-4.0.3-35.el7.i686.rpmLinux
(CESA-2020:3902) libtiff security update libtiff-4.0.3-35.el7.x86_64.rpmLinux
(CESA-2020:3902) libtiff security update libtiff-devel-4.0.3-35.el7.x86_64.rpmLinux
(CESA-2020:3902) libtiff security update libtiff-static-4.0.3-35.el7.x86_64.rpmLinux
(CESA-2020:3902) libtiff security update libtiff-tools-4.0.3-35.el7.x86_64.rpmLinux
(RHSA-2020:3902)Moderate: security update libtiff-debuginfo-4.0.3-35.el7.i686.rpmLinux
(RHSA-2020:3902)Moderate: security update libtiff-debuginfo-4.0.3-35.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234