CVE-2022-4645
published 2023-03-03CVE-2022-4645: LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.43%
34.2th percentile
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tiff | < tiff 4.4.0-5 (bookworm) | tiff 4.4.0-5 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libtiff | libtiff | — | — |
| libtiff | libtiff | 3.5.1 – 4.4.0 | — |
| msrc | cbl2_libtiff_4.5.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_libtiff_4.5.0-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948 allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is
vendor_msrc·2023-03-14·CVSS 5.5
CVE-2022-4645 [MEDIUM] CWE-125 LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948 allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948 allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources the fix is available with commit e8131125.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is
Red Hat
libtiff: out-of-bounds read in tiffcp in tools/tiffcp.c
vendor_redhat·2023-03-01·CVSS 6.8
CVE-2022-4645 [MEDIUM] CWE-125 libtiff: out-of-bounds read in tiffcp in tools/tiffcp.c
libtiff: out-of-bounds read in tiffcp in tools/tiffcp.c
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
A flaw was found in tiffcp, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the tiffcp function in tools/tiffcp.c, resulting in a denial of service and limited information disclosure.
Statement: libtiff is a general purpose library to manipulate TIFF images. The library itself is not used directly, it's used via another application linked with the library, which means this issue can only be triggered by an application processing untrusted
Debian
CVE-2022-4645: tiff - LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowin...
vendor_debian·2022·CVSS 6.8
CVE-2022-4645 [MEDIUM] CVE-2022-4645: tiff - LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowin...
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
Scope: local
bookworm: resolved (fixed in 4.4.0-5)
bullseye: resolved (fixed in 4.2.0-1+deb11u3)
forky: resolved (fixed in 4.4.0-5)
sid: resolved (fixed in 4.4.0-5)
trixie: resolved (fixed in 4.4.0-5)
OSV
CVE-2022-4645: LibTIFF 4
osv·2023-03-03·CVSS 5.5
CVE-2022-4645 [MEDIUM] CVE-2022-4645: LibTIFF 4
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
GHSA
GHSA-6fr2-gj2w-xgr6: LibTIFF 4
ghsa_unreviewed·2023-03-03
CVE-2022-4645 [MEDIUM] CWE-125 GHSA-6fr2-gj2w-xgr6: LibTIFF 4
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4645.jsonhttps://gitlab.com/libtiff/libtiff/-/commit/e813112545942107551433d61afd16ac094ff246https://gitlab.com/libtiff/libtiff/-/issues/277https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ZTFA6GGOKFPIQNHDBMXYUR4XUXUJESE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BA6GRCAQ7NR2OK5N44UQRGUJBIYKWJJH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OLM763GGZVVOAXIQXG6YGTYJ5VFYNECQ/https://security.netapp.com/advisory/ntap-20230331-0001/https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4645.jsonhttps://gitlab.com/libtiff/libtiff/-/commit/e813112545942107551433d61afd16ac094ff246https://gitlab.com/libtiff/libtiff/-/issues/277https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ZTFA6GGOKFPIQNHDBMXYUR4XUXUJESE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BA6GRCAQ7NR2OK5N44UQRGUJBIYKWJJH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OLM763GGZVVOAXIQXG6YGTYJ5VFYNECQ/https://security.netapp.com/advisory/ntap-20230331-0001/
2023-03-03
Published