PT-2022-6895 · Libtiff+8 · Libtiff+8

Published

2022-05-22

·

Updated

2025-06-03

·

CVE-2022-2520

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions libtiff version 4.4.0rc1
Description A flaw in the rotateImage() function in the tiffcrop.c file at line 8621 can cause a program crash when reading a crafted input due to a sysmalloc assertion failure. This issue is related to an incorrect buffer size calculation, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For libtiff version 4.4.0rc1, consider disabling the rotateImage() function as a temporary workaround until a patch is available to prevent potential crashes when reading crafted inputs.

Exploit

Fix

Assertion Failure

Weakness Enumeration

Related Identifiers

ALSA-2023:0095
ALSA-2023:0302
ALT-PU-2022-3360
ALT-PU-2022-3428
ALT-PU-2025-7532
BDU:2023-05419
CESA-2023_0095
CVE-2022-2520
DSA-5333-1
MGASA-2022-0410
OESA-2022-1935
OPENSUSE-SU-2022_3690-1
OPENSUSE-SU-2024:12420-1
RHSA-2023:0095
RHSA-2023:0302
RHSA-2023_0095
RHSA-2023_0302
RLSA-2023:0095
RLSA-2023:0302
SUSE-SU-2022:3679-1
SUSE-SU-2022:3690-1
USN-5714-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Libtiff