CVE-2022-3598

Name
CVE-2022-3598
Description
LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit cfbb883b.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3598.json
MISC https://gitlab.com/libtiff/libtiff/-/issues/435
MISC https://gitlab.com/libtiff/libtiff/-/commit/cfbb883bf6ea7bedcb04177cc4e52d304522fdff
Third Party Advisory https://security.netapp.com/advisory/ntap-20230110-0001/
Third Party Advisory https://lists.debian.org/debian-lts-announce/2023/01/msg00018.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libtiff:libtiff:*:*:*:*:*:*:*:* libtiff >= None <= 4.4.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status