PT-2022-6897 · Libtiff+7 · Libtiff+7

Chintan Shah

+1

·

Published

2022-10-21

·

Updated

2025-06-19

·

CVE-2022-3570

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions libtiff version 4.4.0
Description The issue is related to a buffer overflow in the tiffcrop utility of the libtiff library, which can be triggered by a crafted TIFF image file. This may result in an application crash, potential information disclosure, or other context-dependent impacts. The exploitation of this issue can allow an attacker to cause a denial of service.
Recommendations For libtiff version 4.4.0, consider updating to a newer version that addresses the buffer overflow issue in the tiffcrop utility. As a temporary workaround, restrict the use of the tiffcrop utility until a patch is available. Avoid processing crafted or untrusted TIFF image files with the affected utility to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2340
ALSA-2023_2340
ALT-PU-2025-7185
AZL-11283
BDU:2023-05421
CVE-2022-3570
DLA-3278-1
DSA-5333-1
MGASA-2022-0410
OESA-2022-2020
OPENSUSE-SU-2022_4411-1
OPENSUSE-SU-2024:12604-1
RHSA-2023:2340
RHSA-2023_2340
ROSA-SA-2023-2264
ROSA-SA-2025-2627
SUSE-SU-2022:4411-1
SUSE-SU-2022_4411-1
SUSE-SU-2023:0060-1
SUSE-SU-2023_0060-1
USN-5705-1
USN-5714-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Linuxmint
Red Hat
Suse
Ubuntu
Libtiff