Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-37227 | The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (application crash), a different vulnerability than CVE-2022-0562. When processing a malicious TIFF file, an invalid range may be passed as an argument to the memset() function within TIFFFetchStripThing() in tif_dirread.c. This will cause TIFFFetchStripThing() to segfault after use of an uninitialized resource. |
Tue, 30 Sep 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon amazon Linux
|
|
| CPEs | cpe:2.3:o:amazon:amazon_linux:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Amazon linux 2
|
Amazon amazon Linux
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T09:07:15.683Z
Reserved: 2022-06-21T00:00:00.000Z
Link: CVE-2022-34266
No data.
Status : Modified
Published: 2022-07-19T20:15:11.367
Modified: 2025-09-30T13:40:08.030
Link: CVE-2022-34266
No data.
OpenCVE Enrichment
No data.
EUVD