CVE-2022-4645
Summary
| CVE | CVE-2022-4645 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-03 16:15:00 UTC |
| Updated | 2023-11-07 03:58:00 UTC |
| Description | LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 37 Update: tkimg-1.4.14-3.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 38 Update: tkimg-1.4.14-3.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| 2022/CVE-2022-4645.json · master · GitLab.org / cves · GitLab | CONFIRM | gitlab.com | |
| Merge branch 'InkNames_NumberOfInks_handling_revised' into 'master' (e8131125) · Commits · libtiff / libtiff · GitLab | MISC | gitlab.com | |
| Heap buffer overflow in tiffcp.c:948 (#277) · Issues · libtiff / libtiff · GitLab | MISC | gitlab.com | |
| [SECURITY] Fedora 36 Update: tkimg-1.4.14-3.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: tkimg-1.4.14-3.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE-2022-4645 LibTIFF Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| [SECURITY] Fedora 36 Update: tkimg-1.4.14-3.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: tkimg-1.4.14-3.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: [email protected]
Legacy QID Mappings
- 160618 Oracle Enterprise Linux Security Update for libtiff (ELSA-2023-2340)
- 182983 Debian Security Update for tiff (CVE-2022-4645)
- 241445 Red Hat Update for libtiff (RHSA-2023:2340)
- 283785 Fedora Security Update for tkimg (FEDORA-2023-f5d075f7f2)
- 283786 Fedora Security Update for tkimg (FEDORA-2023-40b675d7ae)
- 284253 Fedora Security Update for tkimg (FEDORA-2023-6c1200da3d)
- 355460 Amazon Linux Security Advisory for libtiff : ALAS2023-2023-230
- 502795 Alpine Linux Security Update for tiff
- 672968 EulerOS Security Update for libtiff (EulerOS-SA-2023-1874)
- 672998 EulerOS Security Update for libtiff (EulerOS-SA-2023-1849)
- 905707 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13826)
- 905722 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13811)
- 906540 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13811-1)
- 906582 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13811-3)
- 906760 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13826-1)
- 906786 Common Base Linux Mariner (CBL-Mariner) Security Update for libtiff (13811-5)
- 941030 AlmaLinux Security Update for libtiff (ALSA-2023:2340)