CVE-2022-0891
Summary
| CVE | CVE-2022-0891 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-10 17:44:00 UTC |
| Updated | 2023-11-07 03:41:00 UTC |
| Description | A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| /tools/tiffcrop.c:6866 - Heap buffer overflow in extractImageSection (#380) · Issues · libtiff / libtiff · GitLab |
MISC |
gitlab.com |
|
| 2022/CVE-2022-0891.json · master · GitLab.org / cves · GitLab |
CONFIRM |
gitlab.com |
|
| tiffcrop: fix issue #380 and #382 heap buffer overflow in extractImageSection (232282fd) · Commits · freedesktop-sdk / mirrors / gitlab / libtiff / libtiff · GitLab |
MISC |
gitlab.com |
|
| [SECURITY] Fedora 35 Update: libtiff-4.3.0-6.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| /tools/tiffcrop.c:6866 - Heap use after free in extractImageSection (#382) · Issues · libtiff / libtiff · GitLab |
MISC |
gitlab.com |
|
| April 2022 LibTIFF Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| LibTIFF: Multiple Vulnerabilities (GLSA 202210-10) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 36 Update: libtiff-4.3.0-6.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: libtiff-4.3.0-6.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 36 Update: libtiff-4.3.0-6.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-5108-1 tiff |
DEBIAN |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Legacy QID Mappings
- 160245 Oracle Enterprise Linux Security Update for libtiff (ELSA-2022-7585)
- 160275 Oracle Enterprise Linux Security Update for libtiff (ELSA-2022-8194)
- 179158 Debian Security Update for tiff (DSA 5108-1)
- 181972 Debian Security Update for tiff (CVE-2022-0891)
- 198786 Ubuntu Security Notification for LibTIFF Vulnerabilities (USN-5421-1)
- 240843 Red Hat Update for libtiff (RHSA-2022:7585)
- 240881 Red Hat Update for libtiff (RHSA-2022:8194)
- 282544 Fedora Security Update for libtiff (FEDORA-2022-e2996202a0)
- 354293 Amazon Linux Security Advisory for libtiff : ALAS2022-2022-049
- 354326 Amazon Linux Security Advisory for libtiff : ALAS2022-2022-194
- 354588 Amazon Linux Security Advisory for libtiff : ALAS-2022-194
- 355159 Amazon Linux Security Advisory for libtiff : ALAS2023-2023-050
- 356436 Amazon Linux Security Advisory for libtiff : ALAS2-2023-2300
- 501505 Alpine Linux Security Update for tiff
- 502035 Alpine Linux Security Update for tiff
- 502793 Alpine Linux Security Update for tiff
- 671568 EulerOS Security Update for libtiff (EulerOS-SA-2022-1573)
- 671688 EulerOS Security Update for compat-libtiff3 (EulerOS-SA-2022-1710)
- 671700 EulerOS Security Update for libtiff (EulerOS-SA-2022-1739)
- 671728 EulerOS Security Update for libtiff (EulerOS-SA-2022-1809)
- 671761 EulerOS Security Update for libtiff (EulerOS-SA-2022-1792)
- 671813 EulerOS Security Update for libtiff (EulerOS-SA-2022-1869)
- 671814 EulerOS Security Update for libtiff (EulerOS-SA-2022-1845)
- 671860 EulerOS Security Update for libtiff (EulerOS-SA-2022-1900)
- 710659 Gentoo Linux LibTIFF Multiple Vulnerabilities (GLSA 202210-10)
- 752138 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2022:1667-1)
- 752188 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2022:1882-1)
- 900746 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (8950)
- 901097 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (8968-1)
- 940761 AlmaLinux Security Update for libtiff (ALSA-2022:7585)
- 940811 AlmaLinux Security Update for libtiff (ALSA-2022:8194)
- 960178 Rocky Linux Security Update for libtiff (RLSA-2022:7585)