{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3alibtifflibtiff/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*","cpe:2.3:a:libtiff:libtiff:4.5.0:-:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.5,"id":"CVE-2023-26966"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libtiff (all versions containing CVE-2023-26966)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["LibTIFF"],"content_html":"\u003cp\u003eThe BSI has reported a vulnerability in libTIFF (tracked as CVE-2023-26966) that permits a local attacker to induce a Denial of Service (DoS) state or achieve memory corruption. This issue arises from improper handling of image data structures within the library, which is widely utilized for TIFF file processing across various desktop and server-side applications. Because libTIFF acts as a foundational dependency for numerous graphics editors, PDF renderers, and web server modules, the exploitability of this flaw depends on the specific application implementation and the privileges of the user interacting with the malicious file. Defenders should prioritize auditing software dependencies for versions of libTIFF containing this vulnerability, particularly in environments where untrusted TIFF files are processed by privileged services or administrative tools.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability potentially allows an attacker to crash critical services or applications, leading to a Denial of Service condition. In more severe scenarios, the underlying memory corruption could theoretically be leveraged for unauthorized code execution, though the report specifically highlights crash-inducing behavior. Systems, services, or users that frequently process arbitrary or externally supplied TIFF images are at the highest risk of exploitation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of applications or services within the enterprise that dynamically link against vulnerable versions of libTIFF.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all software packages and libraries that utilize libTIFF to the latest patched version provided by the upstream maintainers or OS package managers.\u003c/li\u003e\n\u003cli\u003eReview patch management reports for CVE-2023-26966 to identify affected third-party binaries that require manual updates or configuration hardening.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T19:02:56Z","date_published":"2026-09-14T19:02:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-libtiff-dos/","summary":"A memory corruption vulnerability in libTIFF allows a local attacker to cause a crash or Denial of Service condition through a specially crafted TIFF file.","title":"Denial of Service Vulnerability in libTIFF","url":"https://feed.craftedsignal.io/briefs/2026-09-libtiff-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}