CVE-2022-1622
11.05.2022, 15:15
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.Enginsight
Vendor | Product | Version |
---|---|---|
libtiff | libtiff | 4.3.0 |
netapp | ontap_select_deploy_administration_utility | - |
apple | iphone_os | 𝑥 < 16.0 |
apple | macos | 11.0 ≤ 𝑥 < 11.7 |
apple | macos | 12.0 ≤ 𝑥 < 12.6 |
apple | tvos | 𝑥 < 16.0 |
apple | watchos | 𝑥 < 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References