🛡️ USN-6290-1 — tiff

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

tiff vulnerabilities

It was discovered that LibTIFF could be made to write out of bounds when

processing certain malformed image files with the tiffcrop utility. If a

user were tricked into opening a specially crafted image file, an attacker

could possibly use this issue to cause tiffcrop to crash, resulting in a

denial of service, or possibly execute arbitrary code. This issue only

affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.

(CVE-2022-48281)

It was discovered that LibTIFF incorrectly handled certain image files. If

a user were tricked into opening a specially crafted image file, an

attacker could possibly use this issue to cause a denial of service. This

issue only affected Ubuntu 23.04. (CVE-2023-2731)

It was discovered that LibTIFF incorrectly handled certain image files

with the tiffcp utility. If a user were tricked into opening a specially

crafted image file, an attacker could possibly use this issue to cause

tiffcp to crash, resulting in a denial of service. (CVE-2023-2908)

It was discovered that LibTIFF incorrectly handled certain file paths. If

a user were tricked into specifying certain output paths, an attacker

could possibly use this issue to cause a denial of service. This issue

only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-3316)

It was discovered that LibTIFF could be made to write out of bounds when

processing certain malformed image files. If a user were tricked into

opening a specially crafted image file, an attacker could possibly use

this issue to cause a denial of service, or possibly execute arbitrary

code. (CVE-2023-3618)

It was discovered that LibTIFF could be made to write out of bounds when

processing certain malformed image files. If a user were tricked into

opening a specially crafted image file, an attacker could possibly use

this issue to cause a denial of service, or possibly execute arbitrary

code. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and

Ubuntu 23.04. (CVE-2023-25433, CVE-2023-26966)

It was discovered that LibTIFF did not properly managed memory when

processing certain malformed image files with the tiffcrop utility. If a

user were tricked into opening a specially crafted image file, an attacker

could possibly use this issue to cause tiffcrop to crash, resulting in a

denial of service, or possibly execute arbitrary code. This issue only

affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04.

(CVE-2023-26965)

It was discovered that LibTIFF contained an arithmetic overflow. If a user

were tricked into opening a specially crafted image file, an attacker

could possibly use this issue to cause a denial of service.

(CVE-2023-38288, CVE-2023-38289)

Affected software

USN-6290-1 is recorded against 1 package.

  • tiff (fixed in 4.3.0-6ubuntu0.5)

Timeline and source

Published on 15 August 2023 and last revised on 29 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

ubuntu.com (Advisory)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2023-08-15
Updated 2026-08-12
Modified 2026-06-29
Fix URL N/A

Affected Packages

Software From version Fixed in
tiff 4.3.0-6ubuntu0.5

Free Vulnerability Check

Is your site affected by USN-6290-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against USN-6290-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.