PT-2022-6897 · Libtiff+7 · Libtiff+7
Chintan Shah
+1
·
Published
2022-10-21
·
Updated
2025-06-19
·
CVE-2022-3570
CVSS v3.1
7.7
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libtiff version 4.4.0
Description
The issue is related to a buffer overflow in the tiffcrop utility of the libtiff library, which can be triggered by a crafted TIFF image file. This may result in an application crash, potential information disclosure, or other context-dependent impacts. The exploitation of this issue can allow an attacker to cause a denial of service.
Recommendations
For libtiff version 4.4.0, consider updating to a newer version that addresses the buffer overflow issue in the tiffcrop utility. As a temporary workaround, restrict the use of the tiffcrop utility until a patch is available. Avoid processing crafted or untrusted TIFF image files with the affected utility to minimize the risk of exploitation.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Linuxmint
Red Hat
Suse
Ubuntu
Libtiff