Description
LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit cfbb883b.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3278-1 | tiff security update |
EUVD |
EUVD-2022-42962 | LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit cfbb883b. |
Ubuntu USN |
USN-5705-1 | LibTIFF vulnerabilities |
Ubuntu USN |
USN-5714-1 | LibTIFF vulnerabilities |
References
History
Wed, 07 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-05-07T20:33:53.528Z
Reserved: 2022-10-19T00:00:00.000Z
Link: CVE-2022-3598
Updated: 2024-08-03T01:14:02.094Z
Status : Modified
Published: 2022-10-21T16:15:11.030
Modified: 2025-05-07T21:15:56.747
Link: CVE-2022-3598
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN