Name | CVE-2022-2867 |
Description | libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-3278-1, DSA-5333-1 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
tiff (PTS) | buster | 4.1.0+git191117-2~deb10u4 | vulnerable |
| buster (security) | 4.1.0+git191117-2~deb10u8 | fixed |
| bullseye | 4.2.0-1+deb11u4 | fixed |
| bullseye (security) | 4.2.0-1+deb11u5 | fixed |
| bookworm | 4.5.0-6 | fixed |
| bookworm (security) | 4.5.0-6+deb12u1 | fixed |
| trixie | 4.5.1+git230720-1 | fixed |
| sid | 4.5.1+git230720-3 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
tiff | source | buster | 4.1.0+git191117-2~deb10u5 | | DLA-3278-1 | |
tiff | source | bullseye | 4.2.0-1+deb11u3 | | DSA-5333-1 | |
tiff | source | (unstable) | 4.4.0~rc1-1 | | | |
Notes
https://gitlab.com/libtiff/libtiff/-/issues/350
https://gitlab.com/libtiff/libtiff/-/issues/351
https://gitlab.com/libtiff/libtiff/-/commit/07d79fcac2ead271b60e32aeb80f7b4f3be9ac8c (v4.4.0rc1)