A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
{ "vanir_signatures": [ { "signature_type": "Function", "target": { "function": "LZWDecode", "file": "libtiff/tif_lzw.c" }, "source": "https://github.com/libsdl-org/libtiff/commit/9be22b639ea69e102d3847dca4c53ef025e9527b", "id": "CVE-2023-2731-9e1e27c4", "signature_version": "v1", "deprecated": false, "digest": { "function_hash": "245001074140038746663841580373533557202", "length": 5381.0 } }, { "signature_type": "Line", "target": { "file": "libtiff/tif_lzw.c" }, "source": "https://github.com/libsdl-org/libtiff/commit/9be22b639ea69e102d3847dca4c53ef025e9527b", "id": "CVE-2023-2731-c876fe5a", "signature_version": "v1", "deprecated": false, "digest": { "line_hashes": [ "47863501326480845300155871873838596185", "314431711509528890513175766027303822251", "20538631509312112594542715258870283980", "269723995513629474282568554348073905124", "240439446250830314907397831766668572994", "121194476423448759737583876339525208141", "286627866093491271578526113972452842040", "250501192524177400843401446766363376163" ], "threshold": 0.9 } } ] }