Description
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3278-1 | tiff security update |
Debian DSA |
DSA-5333-1 | tiff security update |
EUVD |
EUVD-2022-24675 | A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service. |
Ubuntu USN |
USN-5619-1 | LibTIFF vulnerabilities |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T00:03:06.284Z
Reserved: 2022-04-14T00:00:00.000Z
Link: CVE-2022-1354
No data.
Status : Modified
Published: 2022-08-31T16:15:09.520
Modified: 2024-11-21T06:40:33.447
Link: CVE-2022-1354
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN