Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-72091
HistoryOct 25, 2022 - 12:00 a.m.

LibTIFF Buffer Overflow Vulnerability (CNVD-2022-72091)

2022-10-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
libtiff
buffer overflow
vulnerability
_tiffmemcpy
tiff files
denial of service

0.006 Low

EPSS

Percentile

78.7%

LibTIFF is a library for reading and writing TIFF (Tagged Image File Format) files. The library contains a number of command-line tools for processing TIFF files.LibTIFF suffers from a buffer overflow vulnerability that originates in _TIFFmemcpy in libtiff/tif_unix.c:346, which has an out-of-bounds when called from extractImageSection, tools/tiffcrop.c:6860 write, allowing an attacker to cause a denial of service via a forged tiff file. No detailed vulnerability details are currently available.

CPENameOperatorVersion
libtiff libtiffle4.4.0