libtiff: heap buffer overflow in extractImageSection
Published Mar 9, 2022
7.1
HIGHCVSS 3.1
EPSS 1.54%
Description
A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
Affected products
-
- Version >=3.9.0, <=4.3.0StatusaffectedConstraints-
- Version
Configuration 2
- 10.0
- 11.0
- 35
- 36
Configuration 3
- n/a
No data.
Red Hat Enterprise Linux 8
libtiff-0:4.0.9-23.el8
Fixed · RHSA-2022:7585
Red Hat Enterprise Linux 9
libtiff-0:4.4.0-2.el9
Fixed · RHSA-2022:8194
Red Hat Enterprise Linux 6
libtiff
Out of support scope
Red Hat Enterprise Linux 7
compat-libtiff3
Out of support scope
Red Hat Enterprise Linux 7
libtiff
Out of support scope
Red Hat Enterprise Linux 8
compat-libtiff3
Fix deferred
Red Hat Enterprise Linux 8
mingw-libtiff
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | libtiff-0:4.0.9-23.el8 | Fixed | RHSA-2022:7585 |
| Red Hat Enterprise Linux 9 | libtiff-0:4.4.0-2.el9 | Fixed | RHSA-2022:8194 |
| Red Hat Enterprise Linux 6 | libtiff | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | compat-libtiff3 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libtiff | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | compat-libtiff3 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | mingw-libtiff | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The severity of this flaw was changed to Low because it is an out-of-bounds read of 1 byte and in the tiffcrop tool rather than in the library.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
2 other sources (CVE.org, Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.54% (0.01542) | 74.07th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.55% (0.01555) | 71.85th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.02% (0.00022) | 3.51th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.90% (0.00897) | 83.37th | v3 (v2023.03.01) |
| May 31, 2024 | 0.90% (0.00897) | 82.67th | v3 (v2023.03.01) |
| Apr 3, 2024 | 0.63% (0.00633) | 78.70th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.63% (0.00633) | 76.69th | v3 (v2023.03.01) |
| Oct 29, 2023 | 0.36% (0.00359) | 69.08th | v3 (v2023.03.01) |
| Sep 30, 2023 | 0.33% (0.00329) | 67.51th | v3 (v2023.03.01) |
| Aug 20, 2023 | 0.31% (0.00306) | 65.97th | v3 (v2023.03.01) |
| Jun 14, 2023 | 0.26% (0.00258) | 62.27th | v3 (v2023.03.01) |
| May 8, 2023 | 0.22% (0.00220) | 58.44th | v3 (v2023.03.01) |
| Mar 16, 2023 | 0.16% (0.00161) | 50.96th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.10% (0.00105) | 41.32th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Dec 29, 2022 | 1.54% (0.01537) | 73.91th | v2 (v2022.01.01) |
| Oct 31, 2022 | 1.18% (0.01183) | 60.85th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.11% (0.01108) | 53.57th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Mar 31, 2022 | 1.11% (0.01108) | 30.89th | v2 (v2022.01.01) |
| Mar 16, 2022 | 1.02% (0.01018) | 20.49th | v2 (v2022.01.01) |
| Mar 10, 2022 | 0.95% (0.00950) | 14.38th | v2 (v2022.01.01) |
References (13)
- https://access.redhat.com/security/cve/CVE-2022-0891 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2064411 Issue Tracking
- https://gitlab.com/freedesktop-sdk/mirrors/gitlab/libtiff/libtiff/-/commit/232282fd8f9c21eefe8d2d2b96cdbbb172fe7b7c PatchThird Party Advisory
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0891.json Third Party AdvisoryVDB Entry
- https://gitlab.com/libtiff/libtiff/-/issues/380 ExploitIssue TrackingPatchThird Party Advisory
- https://gitlab.com/libtiff/libtiff/-/issues/382 ExploitIssue TrackingPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RNT2GFNRLOMKJ5KXM6JIHKBNBFDVZPD3/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQ4E654ZYUUUQNBKYQFXNK2CV3CPWTM2/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0891
- https://security.gentoo.org/glsa/202210-10 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20221228-0008/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0891
- https://www.debian.org/security/2022/dsa-5108 vendor-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.