Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2868

Опубликовано: 08 дек. 2021
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.

An improper input validation flaw was found in libtiff's tiffcrop utility. This issue can lead to an out-of-bounds read and cause a crash if an attacker can supply a crafted file to tiffcrop.

Отчет

This flaw is present in the tiffcrop tool only and not in the libtiff library code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libtiffOut of support scope
Red Hat Enterprise Linux 7compat-libtiff3Out of support scope
Red Hat Enterprise Linux 7libtiffOut of support scope
Red Hat Enterprise Linux 8compat-libtiff3Fix deferred
Red Hat Enterprise Linux 9libtiffNot affected
Red Hat Enterprise Linux 8libtiffFixedRHSA-2023:009512.01.2023

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1284
https://bugzilla.redhat.com/show_bug.cgi?id=2118863libtiff: Invalid crop_width and/or crop_length could cause an out-of-bounds read in reverseSamples16bits()

EPSS

Процентиль: 1%
0.00011
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.

CVSS3: 5.5
nvd
почти 3 года назад

libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.

CVSS3: 5.5
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 5.5
debian
почти 3 года назад

libtiff's tiffcrop utility has a improper input validation flaw that c ...

CVSS3: 8.1
github
почти 3 года назад

libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.

EPSS

Процентиль: 1%
0.00011
Низкий

5.5 Medium

CVSS3