PT-2022-7201 · Libtiff+1 · Libtiff+1

Even Rouault

+1

·

Published

2022-04-22

·

Updated

2025-06-03

·

CVE-2022-1623

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions LibTIFF master branch
Description The issue is related to an out-of-bounds read in the LZWDecode function in libtiff/tif lzw.c:624, which can be exploited by attackers to cause a denial-of-service via a crafted tiff file. This can be done remotely.
Recommendations For users that compile libtiff from sources, the fix is available with commit b4e79bfa. As a temporary workaround, consider disabling the LZWDecode function until a patch is available. Restrict access to the libtiff/tif lzw.c module to minimize the risk of exploitation. Avoid using crafted tiff files in the affected LZWDecode function until the issue is resolved.

Exploit

Fix

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2007
ALT-PU-2025-7532
AZL-9734
BDU:2023-09084
CVE-2022-1623
DSA-5333-1
MGASA-2022-0240
OESA-2022-1728

Affected Products

Alt Linux
Libtiff