CVE-2022-1354
published 2022-08-31CVE-2022-1354: A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to…
medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tiff | < tiff 4.3.0-7 (bookworm) | tiff 4.3.0-7 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libtiff | libtiff | < 4.4.0 | 4.4.0 |
| libtiff | libtiff | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv7.5HIGH
OSV
tiff vulnerabilities
osv·2022-09-20·CVSS 7.5
CVE-2020-19131 [HIGH] tiff vulnerabilities
tiff vulnerabilities
It was discovered that LibTIFF was not properly performing the calculation
of data that would eventually be used as a reference for bound-checking
operations. An attacker could possibly use this issue to cause a denial of
service or to expose sensitive information. This issue only affected Ubuntu
18.04 LTS. (CVE-2020-19131)
It was discovered that LibTIFF was not properly terminating a function
execution when processing incorrect data. An attacker could possibly use
this issue to cause a denial of service or to expose sensitive information.
This issue only affected Ubuntu 18.04 LTS. (CVE-2020-19144)
It was discovered that LibTIFF did not properly manage memory under certain
circumstances. If a user were tricked into opening a specially crafted TIFF
file using tiffinf
GHSA
GHSA-8g2j-v7wm-mhv5: A heap buffer overflow flaw was found in Libtiffs' tiffinfo
ghsa_unreviewed·2022-09-01
CVE-2022-1354 [MEDIUM] CWE-125 GHSA-8g2j-v7wm-mhv5: A heap buffer overflow flaw was found in Libtiffs' tiffinfo
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
OSV
CVE-2022-1354: A heap buffer overflow flaw was found in Libtiffs' tiffinfo
osv·2022-08-31·CVSS 5.5
CVE-2022-1354 [MEDIUM] CVE-2022-1354: A heap buffer overflow flaw was found in Libtiffs' tiffinfo
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
Ubuntu
LibTIFF vulnerabilities
vendor_ubuntu·2022-09-20·CVSS 7.5
CVE-2020-19144 [HIGH] LibTIFF vulnerabilities
Title: LibTIFF vulnerabilities
Summary: Several security issues were fixed in LibTIFF.
It was discovered that LibTIFF was not properly performing the calculation
of data that would eventually be used as a reference for bound-checking
operations. An attacker could possibly use this issue to cause a denial of
service or to expose sensitive information. This issue only affected Ubuntu
18.04 LTS. (CVE-2020-19131)
It was discovered that LibTIFF was not properly terminating a function
execution when processing incorrect data. An attacker could possibly use
this issue to cause a denial of service or to expose sensitive information.
This issue only affected Ubuntu 18.04 LTS. (CVE-2020-19144)
It was discovered that LibTIFF did not properly manage memory under certain
circumstances. If a user we
Red Hat
libtiff: heap-buffer-overflow in TIFFReadRawDataStriped() in tiffinfo.c
vendor_redhat·2022-04-12·CVSS 5.5
CVE-2022-1354 [MEDIUM] CWE-125 libtiff: heap-buffer-overflow in TIFFReadRawDataStriped() in tiffinfo.c
libtiff: heap-buffer-overflow in TIFFReadRawDataStriped() in tiffinfo.c
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
Statement: In order to successfully exploit this vulberability, the attacker needs to create a specially crafted TIFF file designed to exploit the buffer overflow in the TIFFRea
Debian
CVE-2022-1354: tiff - A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawData...
vendor_debian·2022·CVSS 5.5
CVE-2022-1354 [MEDIUM] CVE-2022-1354: tiff - A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawData...
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
Scope: local
bookworm: resolved (fixed in 4.3.0-7)
bullseye: resolved (fixed in 4.2.0-1+deb11u3)
forky: resolved (fixed in 4.3.0-7)
sid: resolved (fixed in 4.3.0-7)
trixie: resolved (fixed in 4.3.0-7)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-1354https://bugzilla.redhat.com/show_bug.cgi?id=2074404https://gitlab.com/libtiff/libtiff/-/commit/87f580f39011109b3bb5f6eca13fac543a542798https://gitlab.com/libtiff/libtiff/-/issues/319https://lists.debian.org/debian-lts-announce/2023/01/msg00018.htmlhttps://security.gentoo.org/glsa/202210-10https://security.netapp.com/advisory/ntap-20221014-0007/https://www.debian.org/security/2023/dsa-5333https://access.redhat.com/security/cve/CVE-2022-1354https://bugzilla.redhat.com/show_bug.cgi?id=2074404https://gitlab.com/libtiff/libtiff/-/commit/87f580f39011109b3bb5f6eca13fac543a542798https://gitlab.com/libtiff/libtiff/-/issues/319https://lists.debian.org/debian-lts-announce/2023/01/msg00018.htmlhttps://security.gentoo.org/glsa/202210-10https://security.netapp.com/advisory/ntap-20221014-0007/https://www.debian.org/security/2023/dsa-5333
2022-08-31
Published