libtiff: out-of-bounds read in tiffcp in tools/tiffcp.c
Published Mar 3, 2023
6.8
MEDIUMCVSS 3.1
EPSS 0.43%
Description
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
Affected products
-
- Version <=4.4.0StatusaffectedConstraints-
- Version
Configuration 1
- 36
- 37
- 38
No data.
Red Hat Enterprise Linux 8
libtiff-0:4.0.9-31.el8
Fixed · RHSA-2024:3059
Red Hat Enterprise Linux 9
libtiff-0:4.4.0-7.el9
Fixed · RHSA-2023:2340
Red Hat Enterprise Linux 6
libtiff
Out of support scope
Red Hat Enterprise Linux 7
compat-libtiff3
Out of support scope
Red Hat Enterprise Linux 7
libtiff
Out of support scope
Red Hat Enterprise Linux 8
compat-libtiff3
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | libtiff-0:4.0.9-31.el8 | Fixed | RHSA-2024:3059 |
| Red Hat Enterprise Linux 9 | libtiff-0:4.4.0-7.el9 | Fixed | RHSA-2023:2340 |
| Red Hat Enterprise Linux 6 | libtiff | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | compat-libtiff3 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libtiff | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | compat-libtiff3 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
libtiff is a general purpose library to manipulate TIFF images. The library itself is not used directly, it's used via another application linked with the library, which means this issue can only be triggered by an application processing untrusted images. Therefore, if there is no way an attacker can provide a crafted image to an application, it's likely not possible to exploit this CVE.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-4645 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2176220 Issue Tracking
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4645.json Third Party Advisory
- https://gitlab.com/libtiff/libtiff/-/commit/e813112545942107551433d61afd16ac094ff246 Patch
- https://gitlab.com/libtiff/libtiff/-/issues/277 ExploitIssue TrackingVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ZTFA6GGOKFPIQNHDBMXYUR4XUXUJESE/ vendor-advisoryThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BA6GRCAQ7NR2OK5N44UQRGUJBIYKWJJH/ vendor-advisoryThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OLM763GGZVVOAXIQXG6YGTYJ5VFYNECQ/ vendor-advisoryThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-4645
- https://security.netapp.com/advisory/ntap-20230331-0001/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-4645
Change history (0)
No recorded changes yet.