Back

MEDIUM

libtiff: uint32_t underflow leads to out of bounds read and write in tiffcrop.c

Published Aug 17, 2022

Description

libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation.

Affected products

Remediation

Red Hat statement

This flaw has been rated as a Moderate because it is present in the tiffcrop utility rather than the libtiff library itself.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 17, 2022
Updated Aug 3, 2024
Reserved Aug 16, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 21, 2021