Description
LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6860, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3278-1 | tiff security update |
Debian DSA |
DSA-5333-1 | tiff security update |
EUVD |
EUVD-2022-42987 | LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6860, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191. |
Ubuntu USN |
USN-5714-1 | LibTIFF vulnerabilities |
References
History
Wed, 07 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-05-07T14:57:16.043Z
Reserved: 2022-10-21T00:00:00.000Z
Link: CVE-2022-3627
Updated: 2024-08-03T01:14:02.492Z
Status : Modified
Published: 2022-10-21T16:15:11.197
Modified: 2025-05-07T15:15:54.603
Link: CVE-2022-3627
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN