cbcvebase.
CVE-2022-0561
published 2022-02-11

CVE-2022-0561: Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fix is available with commit eecb0712.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiantiff< tiff 4.3.0-4 (bookworm)tiff 4.3.0-4 (bookworm)
fedoraprojectfedora
libtifflibtiff
libtifflibtiff3.9.0 – 4.3.0
msrccbl2_libtiff_4.3.0-2_on_cbl_mariner_2.0
msrccm1_libtiff_4.1.0-3_on_cbl_mariner_1.0
redhatenterprise_linux

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM