CVE-2022-3598
Summary
| CVE | CVE-2022-3598 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-21 16:15:00 UTC |
| Updated | 2023-03-31 16:05:00 UTC |
| Description | LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit cfbb883b. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| October 2022 LibTIFF Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| 2022/CVE-2022-3598.json · master · GitLab.org / cves · GitLab |
CONFIRM |
gitlab.com |
|
| tiffcrop: heap-buffer-overflow in extractContigSamplesShifted24bits, tiffcrop.c:3604 (#435) · Issues · libtiff / libtiff · GitLab |
MISC |
gitlab.com |
|
| [SECURITY] [DLA 3278-1] tiff security update |
MLIST |
lists.debian.org |
|
| Merge branch 'tiffcrop_fix_#435' into 'master' (cfbb883b) · Commits · libtiff / libtiff · GitLab |
MISC |
gitlab.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Legacy QID Mappings
- 160618 Oracle Enterprise Linux Security Update for libtiff (ELSA-2023-2340)
- 181488 Debian Security Update for tiff (DLA 3278-1)
- 184884 Debian Security Update for tiff (CVE-2022-3598)
- 199019 Ubuntu Security Notification for LibTIFF Vulnerabilities (USN-5714-1)
- 241445 Red Hat Update for libtiff (RHSA-2023:2340)
- 296098 Oracle Solaris 11.4 Support Repository Update (SRU) 52.132.2 Missing (CPUOCT2022)
- 356375 Amazon Linux Security Advisory for libtiff : ALAS2023-2023-364
- 502795 Alpine Linux Security Update for tiff
- 503132 Alpine Linux Security Update for tiff
- 505945 Alpine Linux Security Update for tiff
- 672478 EulerOS Security Update for libtiff (EulerOS-SA-2023-1039)
- 672508 EulerOS Security Update for libtiff (EulerOS-SA-2023-1014)
- 672526 EulerOS Security Update for libtiff (EulerOS-SA-2023-1128)
- 672539 EulerOS Security Update for libtiff (EulerOS-SA-2023-1104)
- 672592 EulerOS Security Update for libtiff (EulerOS-SA-2023-1326)
- 672626 EulerOS Security Update for libtiff (EulerOS-SA-2023-1363)
- 672651 EulerOS Security Update for libtiff (EulerOS-SA-2023-1391)
- 672772 EulerOS Security Update for libtiff (EulerOS-SA-2023-1509)
- 752996 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2022:4411-1)
- 753515 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2023:0060-1)
- 904324 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (11302)
- 904337 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (11285)
- 904807 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (11302-1)
- 905837 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (11302-2)
- 906380 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (11285-2)
- 941030 AlmaLinux Security Update for libtiff (ALSA-2023:2340)