PT-2022-7201 · Libtiff+1 · Libtiff+1
Even Rouault
+1
·
Published
2022-04-22
·
Updated
2025-06-03
·
CVE-2022-1623
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
LibTIFF master branch
Description
The issue is related to an out-of-bounds read in the
LZWDecode function in libtiff/tif lzw.c:624, which can be exploited by attackers to cause a denial-of-service via a crafted tiff file. This can be done remotely.Recommendations
For users that compile libtiff from sources, the fix is available with commit b4e79bfa. As a temporary workaround, consider disabling the
LZWDecode function until a patch is available. Restrict access to the libtiff/tif lzw.c module to minimize the risk of exploitation. Avoid using crafted tiff files in the affected LZWDecode function until the issue is resolved.Exploit
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Libtiff