vulnerability
Amazon Linux 2023: CVE-2022-22844: Important priority package update for libtiff
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:L/AC:L/Au:N/C:N/I:N/A:C) | 2022-01-04 | 2025-02-17 | 2025-02-17 |
Severity
5
CVSS
(AV:L/AC:L/Au:N/C:N/I:N/A:C)
Published
2022-01-04
Added
2025-02-17
Modified
2025-02-17
Description
LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.
A buffer overflow vulnerability was found in libtiff. This flaw allows an attacker with network access to pass specially crafted files, causing an application to halt or crash. The root cause of this issue was from the memcpy function in tif_unix.c.
A buffer overflow vulnerability was found in libtiff. This flaw allows an attacker with network access to pass specially crafted files, causing an application to halt or crash. The root cause of this issue was from the memcpy function in tif_unix.c.
Solution(s)
amazon-linux-2023-upgrade-libtiffamazon-linux-2023-upgrade-libtiff-debuginfoamazon-linux-2023-upgrade-libtiff-debugsourceamazon-linux-2023-upgrade-libtiff-develamazon-linux-2023-upgrade-libtiff-staticamazon-linux-2023-upgrade-libtiff-toolsamazon-linux-2023-upgrade-libtiff-tools-debuginfo

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.