LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
References
Configurations
History
18 Mar 2025, 20:27
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
|
First Time |
Fedoraproject fedora
Fedoraproject |
|
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ZTFA6GGOKFPIQNHDBMXYUR4XUXUJESE/ - Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BA6GRCAQ7NR2OK5N44UQRGUJBIYKWJJH/ - Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OLM763GGZVVOAXIQXG6YGTYJ5VFYNECQ/ - Third Party Advisory | |
References | () https://security.netapp.com/advisory/ntap-20230331-0001/ - Third Party Advisory |
Information
Published : 2023-03-03 16:15
Updated : 2025-04-04 21:15
NVD link : CVE-2022-4645
Mitre link : CVE-2022-4645
CVE.ORG link : CVE-2022-4645
JSON object : View
Products Affected
libtiff
- libtiff
fedoraproject
- fedora
CWE
CWE-125
Out-of-bounds Read