Lucene search

K
osvGoogleOSV:CVE-2023-30775
HistoryMay 19, 2023 - 3:15 p.m.

CVE-2023-30775

2023-05-1915:15:08
Google
osv.dev
9
vulnerability
libtiff
heap buffer overflow
extractcontigsamples32bits
tiffcrop.c

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

7.7

Confidence

Low

EPSS

0.001

Percentile

20.5%

A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

7.7

Confidence

Low

EPSS

0.001

Percentile

20.5%