Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-3627
HistoryOct 21, 2022 - 12:00 a.m.

CVE-2022-3627

2022-10-2100:00:00
ubuntu.com
ubuntu.com
13
libtiff
out-of-bounds write
denial-of-service
crafted file
vulnerability

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.006 Low

EPSS

Percentile

78.7%

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in
libtiff/tif_unix.c:346 when called from extractImageSection,
tools/tiffcrop.c:6860, allowing attackers to cause a denial-of-service via
a crafted tiff file. For users that compile libtiff from sources, the fix
is available with commit 236b7191.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu22.10noarchtiff< 4.4.0-4ubuntu3.1UNKNOWN

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.006 Low

EPSS

Percentile

78.7%