libtiff: tiffcrop.c has uint32_t underflow which leads to out of bounds read and write in extractContigSamples8bits()
Published Aug 17, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.32%
Description
libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples8bits routine. An attacker who supplies a crafted file to tiffcrop could trigger this flaw, most likely by tricking a user into opening the crafted file with tiffcrop. Triggering this flaw could cause a crash or potentially further exploitation.
Affected products
- Vendor n/a Product Libtiff Defaultn/a
- Version libtiff 4.4.0rc1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Libtiff | n/a |
|
Configuration 2
- 35
- 36
Configuration 3
- 10.0
- 11.0
No data.
Red Hat Enterprise Linux 8
libtiff-0:4.0.9-26.el8_7
Fixed · RHSA-2023:0095
Red Hat Enterprise Linux 6
libtiff
Out of support scope
Red Hat Enterprise Linux 7
compat-libtiff3
Out of support scope
Red Hat Enterprise Linux 7
libtiff
Out of support scope
Red Hat Enterprise Linux 8
compat-libtiff3
Will not fix
Red Hat Enterprise Linux 9
libtiff
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | libtiff-0:4.0.9-26.el8_7 | Fixed | RHSA-2023:0095 |
| Red Hat Enterprise Linux 6 | libtiff | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | compat-libtiff3 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libtiff | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | compat-libtiff3 | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | libtiff | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is present only in the tiffcrop tool, not in the libtiff library code.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-2869 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2118869 Issue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/01/msg00018.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2869
- https://www.cve.org/CVERecord?id=CVE-2022-2869
- https://www.debian.org/security/2023/dsa-5333 vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2869 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2118869 | Issue TrackingPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/01/msg00018.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2869 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-2869 | ||
| https://www.debian.org/security/2023/dsa-5333 | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.