CVE-2022-2953
29.08.2022, 15:15
LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 48d6ece8.Enginsight
Vendor | Product | Version |
---|---|---|
libtiff | libtiff | 𝑥 ≤ 4.4.0 |
netapp | ontap_select_deploy_administration_utility | - |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References