CVE-2022-22844

Name
CVE-2022-22844
Description
LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://gitlab.com/libtiff/libtiff/-/issues/355
MISC https://gitlab.com/libtiff/libtiff/-/merge_requests/287
MLIST https://lists.debian.org/debian-lts-announce/2022/03/msg00001.html
CONFIRM https://security.netapp.com/advisory/ntap-20220311-0002/
DEBIAN https://www.debian.org/security/2022/dsa-5108
Third Party Advisory https://security.gentoo.org/glsa/202210-10

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libtiff:libtiff:4.3.0:*:*:*:*:*:*:* libtiff == None == 4.3.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status