Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-0562
HistoryFeb 11, 2022 - 12:00 a.m.

CVE-2022-0562

2022-02-1100:00:00
ubuntu.com
ubuntu.com
19
cve-2022-0562
memcpy function
tiffreaddirectory
tif_dirread.c
libtiff
denial of service
crafted tiff file
compile from sources
fix available
commit 561599c
unix

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

49.0%

Null source pointer passed as an argument to memcpy() function within
TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0
could lead to Denial of Service via crafted TIFF file. For users that
compile libtiff from sources, a fix is available with commit 561599c.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchtiff< 4.0.9-5ubuntu0.5UNKNOWN
ubuntu20.04noarchtiff< 4.1.0+git191117-2ubuntu0.20.04.3UNKNOWN
ubuntu21.10noarchtiff< 4.3.0-1ubuntu0.1UNKNOWN
ubuntu14.04noarchtiff< 4.0.3-7ubuntu0.11+esm1UNKNOWN
ubuntu16.04noarchtiff< 4.0.6-1ubuntu0.8+esm1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

49.0%