CVE-2023-26966
MEDIUMlibtiff <4.5.0 - Buffer Overflow
Title source: llmDescription
libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and specifies the output to be big-endian.
References (4)
Scores
CVSS v3
5.5
EPSS
0.0003
EPSS Percentile
7.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Classification
CWE
CWE-120
Status
published
Affected Products (1)
libtiff/libtiff
Timeline
Published
Jun 29, 2023
Tracked Since
Feb 18, 2026