PT-2022-7200 · Libtiff+3 · Libtiff+3

Antonio Zekic

+2

·

Published

2022-03-30

·

Updated

2025-06-03

·

CVE-2022-1622

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions LibTIFF master branch
Description The issue is related to an out-of-bounds read in the LZWDecode function in libtiff/tif lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. This can be exploited by a remote attacker to disrupt service.
Recommendations For users that compile libtiff from sources, the fix is available with commit b4e79bfa. As a temporary workaround, consider disabling the LZWDecode function until a patch is available. Restrict access to crafted tiff files to minimize the risk of exploitation.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2007
ALT-PU-2025-7532
AZL-9733
BDU:2023-09083
CVE-2022-1622
DSA-5333-1
MGASA-2022-0240
OESA-2022-1728
SUSE-SU-2023:4736-1
SUSE-SU-2023:4869-1
SUSE-SU-2023_4736-1
SUSE-SU-2023_4869-1

Affected Products

Alt Linux
Libtiff
Apple Macos
Suse