CVE-2022-3570

NameCVE-2022-3570
DescriptionMultiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3278-1, DSA-5333-1, ELA-786-1
Debian Bugs1022555

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tiff (PTS)jessie, jessie (lts)4.0.3-12.3+deb8u16fixed
stretch (security)4.0.8-2+deb9u8vulnerable
stretch (lts), stretch4.0.8-2+deb9u11fixed
buster4.1.0+git191117-2~deb10u4vulnerable
buster (security)4.1.0+git191117-2~deb10u9fixed
bullseye (security), bullseye4.2.0-1+deb11u5fixed
bookworm (security), bookworm4.5.0-6+deb12u1fixed
sid, trixie4.5.1+git230720-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tiffsourcejessie4.0.3-12.3+deb8u14ELA-786-1
tiffsourcestretch4.0.8-2+deb9u9ELA-786-1
tiffsourcebuster4.1.0+git191117-2~deb10u5DLA-3278-1
tiffsourcebullseye4.2.0-1+deb11u3DSA-5333-1
tiffsource(unstable)4.4.0-51022555

Notes

https://gitlab.com/libtiff/libtiff/-/commit/cfbb883bf6ea7bedcb04177cc4e52d304522fdff (v4.5.0rc1)
https://gitlab.com/libtiff/libtiff/-/issues/381
https://gitlab.com/libtiff/libtiff/-/issues/386

Search for package or bug name: Reporting problems