CVE-2022-2953
29.08.2022, 15:15
LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 48d6ece8.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libtiff | libtiff | 𝑥 ≤ 4.4.0 |
| netapp | ontap_select_deploy_administration_utility | - |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| libtiff |
| ||||
| libtiff-debuginfo |
| ||||
| libtiff-debugsource |
| ||||
| libtiff-devel |
| ||||
| libtiff-static |
| ||||
| libtiff-tools |
| ||||
| libtiff-tools-debuginfo |
|
Azure Linux Releases
Common Weakness Enumeration
References