CVE-2022-2953

Name
CVE-2022-2953
Description
LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 48d6ece8.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://gitlab.com/libtiff/libtiff/-/commit/48d6ece8389b01129e7d357f0985c8f938ce3da3
MISC https://gitlab.com/libtiff/libtiff/-/issues/414
CONFIRM https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2953.json
Third Party Advisory https://security.netapp.com/advisory/ntap-20221014-0008/
Third Party Advisory https://www.debian.org/security/2023/dsa-5333

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:* libtiff >= None <= 4.4.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status