A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
[
{
"source": "https://github.com/libsdl-org/libtiff/commit/9be22b639ea69e102d3847dca4c53ef025e9527b",
"id": "CVE-2023-2731-9e1e27c4",
"digest": {
"function_hash": "245001074140038746663841580373533557202",
"length": 5381.0
},
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "LZWDecode",
"file": "libtiff/tif_lzw.c"
},
"signature_type": "Function"
},
{
"source": "https://github.com/libsdl-org/libtiff/commit/9be22b639ea69e102d3847dca4c53ef025e9527b",
"id": "CVE-2023-2731-c876fe5a",
"digest": {
"line_hashes": [
"47863501326480845300155871873838596185",
"314431711509528890513175766027303822251",
"20538631509312112594542715258870283980",
"269723995513629474282568554348073905124",
"240439446250830314907397831766668572994",
"121194476423448759737583876339525208141",
"286627866093491271578526113972452842040",
"250501192524177400843401446766363376163"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "libtiff/tif_lzw.c"
},
"signature_type": "Line"
}
]