First published: Mon Mar 07 2022(Updated: )
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/tiff | 4.1.0+git191117-2~deb10u4 4.1.0+git191117-2~deb10u8 4.2.0-1+deb11u4 4.5.0-6 4.5.1+git230720-1 | |
TIFF | =4.3.0 | |
Debian Linux | =10.0 | |
Debian Linux | =11.0 | |
Red Hat Fedora | =36 | |
NetApp Active IQ Unified Manager for VMware vSphere |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0865 has been classified as a denial-of-service vulnerability.
To fix CVE-2022-0865, users should update to libtiff version 4.5.1 or later.
CVE-2022-0865 affects libtiff version 4.3.0 and certain Debian and Fedora package versions.
CVE-2022-0865 allows attackers to cause a denial-of-service via a crafted TIFF file.
Yes, a patch for CVE-2022-0865 is available from the libtiff commit 5e180045.