Your submission was sent successfully! Close

CVE-2022-1354

Published: 31 August 2022

A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.

Priority

Medium

CVSS 3 base score: 5.5

Status

Package Release Status
tiff
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(code not present)
focal
Released (4.1.0+git191117-2ubuntu0.20.04.5)
impish Ignored
(reached end-of-life)
jammy
Released (4.3.0-6ubuntu0.1)
trusty Not vulnerable
(code not present)
upstream
Released (4.3.0-7)
xenial Not vulnerable
(code not present)