CVE-2023-41175

Updated: 2026-02-27 01:34:26.491545

Description:

A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU libtiff 4.4.0 6.5 MEDIUM Released CLSA-2025:1745531344 2025-04-26 03:59:34
CentOS 7 ELS libtiff 4.0.3 6.5 MEDIUM Ignored 2024-07-02 11:10:28 Ignored due to low severity