Libtiff · Libtiff · CVE-2022-4645
**Name of the Vulnerable Software and Affected Versions**
LibTIFF version 4.4.0
**Description**
The issue is related to an out-of-bounds read in the `tiffcp` utility, located in `tools/tiffcp.c:948`, which can be exploited by attackers to cause a denial-of-service via a crafted tiff file. This can lead to a disruption in service.
**Recommendations**
For LibTIFF version 4.4.0, users who compile libtiff from sources can apply the fix available with commit e8131125 to resolve the issue. As a temporary workaround, consider restricting the use of the `tiffcp` utility until the fix is applied.