PT-2022-6896 · Libtiff+9 · Libtiff+9

Todd Cullum

·

Published

2022-06-07

·

Updated

2025-06-03

·

CVE-2022-2868

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libtiff versions (affected versions not specified)
Description The issue is related to an improper input validation flaw in libtiff's tiffcrop utility. This flaw can lead to an out of bounds read, causing a crash if an attacker supplies a crafted file to tiffcrop. There is no information provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

ALSA-2023:0095
ALT-PU-2022-2007
ALT-PU-2022-3428
ALT-PU-2025-7532
AZL-10568
BDU:2023-05420
CESA-2023_0095
CVE-2022-2868
DLA-3278-1
DSA-5333-1
MGASA-2022-0337
OESA-2022-1869
OPENSUSE-SU-2022_3690-1
OPENSUSE-SU-2024:13381-1
RHSA-2023:0095
RHSA-2023_0095
RLSA-2023:0095
ROSA-SA-2023-2264
SUSE-SU-2022:3679-1
SUSE-SU-2022:3690-1
USN-5604-1
USN-5714-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Libtiff