Skip to content

Instantly share code, notes, and snippets.

@CamberLoid
Created July 2, 2023 17:01
Show Gist options
  • Save CamberLoid/3375e4d1050d0795724d07e936ca1304 to your computer and use it in GitHub Desktop.
Save CamberLoid/3375e4d1050d0795724d07e936ca1304 to your computer and use it in GitHub Desktop.

libTIFF / High Severity

It was discovered that LibTIFF could be made to read out of bounds when processing certain malformed image files with the tiffcrop tool. If a user were tricked into opening a specially crafted image file, an attacker could possibly use this issue to cause tiffcrop to crash, resulting in a denial of service. (CVE-2023-0795, CVE-2023-0796, CVE-2023-0797, CVE-2023-0798, CVE-2023-0799)

It was discovered that LibTIFF could be made to write out of bounds when processing certain malformed image files with the tiffcrop tool. If a user were tricked into opening a specially crafted image file, an attacker could possibly use this issue to cause tiffcrop to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-0800, CVE-2023-0801, CVE-2023-0802, CVE-2023-0803, CVE-2023-0804)


squashfs-tools / TBA

CVE: CVE-2021-40153/41072

Impact: Arbitrary write of file

Severity escalation: Used in deploykit Fix: use patchset


GNU tar tar / Moderate Severity (Escalated from low)


Vim + gVim


Tor /


requests / Moderates/High Severity

  • CVE: CVE-2023-32681
  • Current Version: 2.26
  • Impact: Leak HTTP Proxy-Authorization header
  • Applicable CWEs: CWE-200
  • Fix: 2.31.0+

thunderbird&js-102 / TBA

  • CVE: CVE-2023-34416
  • Fix: 102.12+

libraw / Low Severity

  • CVE: CVE-2021-32142, CVE-2023-1729
  • Ref: DSA (), USN ()
  • Weakness: Buffer overflow
  • Impact is limited to crash the libraw
  • Fix: 0.20.2+ (latest is 0.21.1)

wireshark / TBA

  • CVE: TOO MANY!
  • Ref

c-ares / TBA

  • CVE: CVE-2021-3672,

CPAN.pm (component of perl) / Low S.

  • CVE: CVE-2023-31484
  • Desc: does not verify TLS certificates when downloading distributions over HTTPS. May lead to MITM

gpac / TBA

  • CVE: TOO MANY!
  • Fix:
    • Update 2.x, may require further work
    • Follow Debian's backport

node / TBA, consider separate topic?

  • CVE: TOO MANY
  • Fix
    • 16.latest (in 2023H1)
    • 18.latest (separate)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment