CVE-2023-52355

Executive Summary

CVE-2023-52355: An out-of-memory vulnerability in libtiff’s TIFFRasterScanlineSize64() can be triggered by a crafted TIFF file smaller than 379 KB, allowing a remote attacker to cause a denial‑of‑service. The flaw is not yet listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2024-01-25T20:15:38.353 - Last Modified: 2026-09-30T18:17:52.547

Original Description: An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

"Difficulties are things that show a person what they are."

— Epictetus
Source: NVD