Your submission was sent successfully! Close

CVE-2022-1355

Published: 31 August 2022

A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.

Priority

Medium

CVSS 3 base score: 6.1

Status

Package Release Status
tiff
Launchpad, Ubuntu, Debian
bionic
Released (4.0.9-5ubuntu0.7)
focal
Released (4.1.0+git191117-2ubuntu0.20.04.5)
impish Ignored
(reached end-of-life)
jammy
Released (4.3.0-6ubuntu0.1)
trusty
Released (4.0.3-7ubuntu0.11+esm4)
upstream
Released (4.3.0-7)
xenial
Released (4.0.6-1ubuntu0.8+esm4)