libtiff: heap Buffer overflows in tiffcrop.c
Published Oct 21, 2022
7.7
HIGHCVSS 3.1
EPSS 0.51%
Description
Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
Affected products
-
- Version >=3.9.0, <=4.4.0StatusaffectedConstraints-
- Version
Configuration 2
- 10.0
- 11.0
No data.
Red Hat Enterprise Linux 9
libtiff-0:4.4.0-7.el9
Fixed · RHSA-2023:2340
Red Hat Enterprise Linux 6
libtiff
Out of support scope
Red Hat Enterprise Linux 7
compat-libtiff3
Out of support scope
Red Hat Enterprise Linux 7
libtiff
Out of support scope
Red Hat Enterprise Linux 8
compat-libtiff3
Affected
Red Hat Enterprise Linux 8
libtiff
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | libtiff-0:4.4.0-7.el9 | Fixed | RHSA-2023:2340 |
| Red Hat Enterprise Linux 6 | libtiff | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | compat-libtiff3 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libtiff | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | compat-libtiff3 | Affected | n/a |
| Red Hat Enterprise Linux 8 | libtiff | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-3570 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2142734 Issue Tracking
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3570.json Third Party AdvisoryVDB Entry
- https://gitlab.com/libtiff/libtiff/-/commit/bd94a9b383d8755a27b5a1bc27660b8ad10b094c Patch
- https://gitlab.com/libtiff/libtiff/-/issues/381 ExploitIssue TrackingPatchThird Party Advisory
- https://gitlab.com/libtiff/libtiff/-/issues/386 ExploitIssue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/01/msg00018.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3570
- https://security.netapp.com/advisory/ntap-20230203-0002/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-3570
- https://www.debian.org/security/2023/dsa-5333 vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3570 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2142734 | Issue Tracking | |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3570.json | Third Party AdvisoryVDB Entry | |
| https://gitlab.com/libtiff/libtiff/-/commit/bd94a9b383d8755a27b5a1bc27660b8ad10b094c | Patch | |
| https://gitlab.com/libtiff/libtiff/-/issues/381 | ExploitIssue TrackingPatchThird Party Advisory | |
| https://gitlab.com/libtiff/libtiff/-/issues/386 | ExploitIssue TrackingPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/01/msg00018.html | mailing-listMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3570 | ||
| https://security.netapp.com/advisory/ntap-20230203-0002/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-3570 | ||
| https://www.debian.org/security/2023/dsa-5333 | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.