Back

MEDIUM

libtiff: reachable assertion

Published Mar 7, 2022

Description

Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.

Affected products

Remediation

Red Hat mitigation

Applications that do not parse files from untrusted/malicious sources will not be affected by this vulnerability.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Mar 7, 2022
Updated Aug 2, 2024
Reserved Mar 4, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 1, 2022