CVE-2022-3970

NameCVE-2022-3970
DescriptionA vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 227500897dfb07fb7d27f7aa570050e62617e3be. It is recommended to apply a patch to fix this issue. The identifier VDB-213549 was assigned to this vulnerability.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3278-1, DSA-5333-1
Debian Bugs1024737

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tiff (PTS)buster4.1.0+git191117-2~deb10u4vulnerable
buster (security)4.1.0+git191117-2~deb10u7fixed
bullseye4.2.0-1+deb11u1vulnerable
bullseye (security)4.2.0-1+deb11u4fixed
bookworm, sid4.5.0-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tiffsourcebuster4.1.0+git191117-2~deb10u5DLA-3278-1
tiffsourcebullseye4.2.0-1+deb11u3DSA-5333-1
tiffsource(unstable)4.4.0-61024737

Notes

https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=53137
https://gitlab.com/libtiff/libtiff/-/commit/227500897dfb07fb7d27f7aa570050e62617e3be
https://oss-fuzz.com/download?testcase_id=5738253143900160

Search for package or bug name: Reporting problems