cbcvebase.
CVE-2022-1355
published 2022-08-31

CVE-2022-1355: A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool…

medium6.1CVSS 3.1
AVLACLPRNUIRSUCNILAH
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiantiff< tiff 4.3.0-8 (bookworm)tiff 4.3.0-8 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
libtifflibtiff< 4.4.04.4.0
libtifflibtiff
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
osv7.5HIGH