CVE-2022-1355
published 2022-08-31CVE-2022-1355: A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool…
medium6.1CVSS 3.1
AVLACLPRNUIRSUCNILAH
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tiff | < tiff 4.3.0-8 (bookworm) | tiff 4.3.0-8 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libtiff | libtiff | < 4.4.0 | 4.4.0 |
| libtiff | libtiff | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
osv7.5HIGH
OSV
tiff vulnerabilities
osv·2022-09-20·CVSS 7.5
CVE-2020-19131 [HIGH] tiff vulnerabilities
tiff vulnerabilities
It was discovered that LibTIFF was not properly performing the calculation
of data that would eventually be used as a reference for bound-checking
operations. An attacker could possibly use this issue to cause a denial of
service or to expose sensitive information. This issue only affected Ubuntu
18.04 LTS. (CVE-2020-19131)
It was discovered that LibTIFF was not properly terminating a function
execution when processing incorrect data. An attacker could possibly use
this issue to cause a denial of service or to expose sensitive information.
This issue only affected Ubuntu 18.04 LTS. (CVE-2020-19144)
It was discovered that LibTIFF did not properly manage memory under certain
circumstances. If a user were tricked into opening a specially crafted TIFF
file using tiffinf
GHSA
GHSA-2fqh-vmvf-c822: A stack buffer overflow flaw was found in Libtiffs' tiffcp
ghsa_unreviewed·2022-09-01
CVE-2022-1355 [MEDIUM] CWE-119 GHSA-2fqh-vmvf-c822: A stack buffer overflow flaw was found in Libtiffs' tiffcp
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
OSV
CVE-2022-1355: A stack buffer overflow flaw was found in Libtiffs' tiffcp
osv·2022-08-31·CVSS 6.1
CVE-2022-1355 [MEDIUM] CVE-2022-1355: A stack buffer overflow flaw was found in Libtiffs' tiffcp
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
Ubuntu
LibTIFF vulnerabilities
vendor_ubuntu·2022-09-20·CVSS 7.5
CVE-2020-19144 [HIGH] LibTIFF vulnerabilities
Title: LibTIFF vulnerabilities
Summary: Several security issues were fixed in LibTIFF.
It was discovered that LibTIFF was not properly performing the calculation
of data that would eventually be used as a reference for bound-checking
operations. An attacker could possibly use this issue to cause a denial of
service or to expose sensitive information. This issue only affected Ubuntu
18.04 LTS. (CVE-2020-19131)
It was discovered that LibTIFF was not properly terminating a function
execution when processing incorrect data. An attacker could possibly use
this issue to cause a denial of service or to expose sensitive information.
This issue only affected Ubuntu 18.04 LTS. (CVE-2020-19144)
It was discovered that LibTIFF did not properly manage memory under certain
circumstances. If a user we
Red Hat
libtiff: stack-buffer-overflow in tiffcp.c in main()
vendor_redhat·2022-04-12·CVSS 6.1
CVE-2022-1355 [MEDIUM] CWE-787 libtiff: stack-buffer-overflow in tiffcp.c in main()
libtiff: stack-buffer-overflow in tiffcp.c in main()
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
Package: libtiff (Red Hat Enterprise Linux 6) - Not affected
Package: compat-libtiff3 (Red Hat Enterprise Linux 7) - Not affected
Package: libtiff (Red Hat Enterprise L
Debian
CVE-2022-1355: tiff - A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function....
vendor_debian·2022·CVSS 6.1
CVE-2022-1355 [MEDIUM] CVE-2022-1355: tiff - A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function....
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
Scope: local
bookworm: resolved (fixed in 4.3.0-8)
bullseye: resolved (fixed in 4.2.0-1+deb11u3)
forky: resolved (fixed in 4.3.0-8)
sid: resolved (fixed in 4.3.0-8)
trixie: resolved (fixed in 4.3.0-8)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2022-1355https://bugzilla.redhat.com/show_bug.cgi?id=2074415https://gitlab.com/libtiff/libtiff/-/issues/400https://gitlab.com/libtiff/libtiff/-/merge_requests/323https://lists.debian.org/debian-lts-announce/2023/01/msg00018.htmlhttps://security.gentoo.org/glsa/202210-10https://security.netapp.com/advisory/ntap-20221014-0007/https://www.debian.org/security/2023/dsa-5333https://access.redhat.com/security/cve/CVE-2022-1355https://bugzilla.redhat.com/show_bug.cgi?id=2074415https://gitlab.com/libtiff/libtiff/-/issues/400https://gitlab.com/libtiff/libtiff/-/merge_requests/323https://lists.debian.org/debian-lts-announce/2023/01/msg00018.htmlhttps://security.gentoo.org/glsa/202210-10https://security.netapp.com/advisory/ntap-20221014-0007/https://www.debian.org/security/2023/dsa-5333
2022-08-31
Published