Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-2521
HistoryAug 31, 2022 - 12:00 a.m.

CVE-2022-2521

2022-08-3100:00:00
ubuntu.com
ubuntu.com
27
libtiff 4.4.0rc1
invalid pointer free
tiffclose
tif_close.c
tiffcrop.c

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

47.0%

It was found in libtiff 4.4.0rc1 that there is an invalid pointer free
operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that
can cause a program crash and denial of service while processing crafted
input.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu22.10noarchtiff< 4.4.0-4ubuntu3.1UNKNOWN
ubuntu23.04noarchtiff< 4.4.0-4ubuntu3.1UNKNOWN

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

47.0%