CVE-2022-0865: Medium severity tiff vulnerability
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.
Other sources
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources.
Upstream fix: https://gitlab.com/libtiff/libtiff/-/mergerequests/306
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0865?
CVE-2022-0865 has been classified as a denial-of-service vulnerability.
How do I fix CVE-2022-0865?
To fix CVE-2022-0865, users should update to libtiff version 4.5.1 or later.
What software is affected by CVE-2022-0865?
CVE-2022-0865 affects libtiff version 4.3.0 and certain Debian and Fedora package versions.
What kind of attack does CVE-2022-0865 allow?
CVE-2022-0865 allows attackers to cause a denial-of-service via a crafted TIFF file.
Is there a patch available for CVE-2022-0865?
Yes, a patch for CVE-2022-0865 is available from the libtiff commit 5e180045.