CVE-2022-3970
Summary
| CVE | CVE-2022-3970 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-13 08:15:00 UTC |
| Updated | 2023-11-17 19:04:00 UTC |
| Description | A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| About the security content of iOS 16.6 and iPadOS 16.6 - Apple Support |
CONFIRM |
support.apple.com |
|
| About the security content of macOS Ventura 13.5 - Apple Support |
CONFIRM |
support.apple.com |
|
| Log in |
N/A |
oss-fuzz.com |
|
| 53137 -
oss-fuzz -
OSS-Fuzz: Fuzzing the planet -
Monorail |
N/A |
bugs.chromium.org |
|
| CVE-2022-3970 | LibTIFF tif_getimage.c TIFFReadRGBATileExt integer overflow |
N/A |
vuldb.com |
|
| TIFFReadRGBATileExt(): fix (unsigned) integer overflow on strips/tiles > 2 GB (22750089) · Commits · libtiff / libtiff · GitLab |
N/A |
gitlab.com |
|
| CVE-2022-3970 LibTIFF Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] [DLA 3278-1] tiff security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160618 Oracle Enterprise Linux Security Update for libtiff (ELSA-2023-2340)
- 160656 Oracle Enterprise Linux Security Update for libtiff (ELSA-2023-2883)
- 181488 Debian Security Update for tiff (DLA 3278-1)
- 183428 Debian Security Update for tiff (CVE-2022-3970)
- 199058 Ubuntu Security Notification for LibTIFF Vulnerability (USN-5743-2)
- 199525 Ubuntu Security Notification for LibTIFF Vulnerabilities (USN-5841-1)
- 241445 Red Hat Update for libtiff (RHSA-2023:2340)
- 241478 Red Hat Update for libtiff (RHSA-2023:2883)
- 354139 Amazon Linux Security Advisory for libtiff : ALAS2-2022-1891
- 354256 Amazon Linux Security Advisory for libtiff : ALAS-2022-1644
- 354276 Amazon Linux Security Advisory for libtiff : ALAS2022-2022-256
- 354319 Amazon Linux Security Advisory for libtiff : ALAS-2022-256
- 354556 Amazon Linux Security Advisory for libtiff : ALAS-2022-256
- 355159 Amazon Linux Security Advisory for libtiff : ALAS2023-2023-050
- 502692 Alpine Linux Security Update for tiff
- 502795 Alpine Linux Security Update for tiff
- 503132 Alpine Linux Security Update for tiff
- 505945 Alpine Linux Security Update for tiff
- 672526 EulerOS Security Update for libtiff (EulerOS-SA-2023-1128)
- 672539 EulerOS Security Update for libtiff (EulerOS-SA-2023-1104)
- 672626 EulerOS Security Update for libtiff (EulerOS-SA-2023-1363)
- 672651 EulerOS Security Update for libtiff (EulerOS-SA-2023-1391)
- 672680 EulerOS Security Update for libtiff (EulerOS-SA-2023-1427)
- 672688 EulerOS Security Update for libtiff (EulerOS-SA-2023-1412)
- 672867 EulerOS Security Update for libtiff (EulerOS-SA-2023-1599)
- 673076 EulerOS Security Update for libtiff (EulerOS-SA-2023-2157)
- 673113 EulerOS Security Update for compat-libtiff3 (EulerOS-SA-2023-2138)
- 752842 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2022:4259-1)
- 752869 SUSE Enterprise Linux Security Update for tiff (SUSE-SU-2022:4248-1)
- 904506 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (11451)
- 904507 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (11449)
- 904553 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (11451-1)
- 904578 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (11449-1)
- 941030 AlmaLinux Security Update for libtiff (ALSA-2023:2340)
- 941082 AlmaLinux Security Update for libtiff (ALSA-2023:2883)