Bugzilla – Bug 1212397
VUL-0: CVE-2023-25434: tiff: Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215
Last modified: 2023-06-15 07:09:24 UTC
CVE-2023-25434 libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-25434 https://bugzilla.redhat.com/show_bug.cgi?id=2215209 https://www.cve.org/CVERecord?id=CVE-2023-25434 https://gitlab.com/libtiff/libtiff/-/issues/519
I can't reproduce the ASAN crash on all codestreams. Not affected