CVE-2023-2731

MEDIUM

Libtiff < 4.5.0 - NULL Pointer Dereference

Title source: rule
STIX 2.1

Description

A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 1.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (3)
fedoraproject/fedora 38
libtiff/libtiff < 4.5.0
redhat/enterprise_linux 9.0
Published May 17, 2023
Tracked Since Feb 18, 2026