CVE-2022-0924: Medium severity tiff vulnerability
Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0924?
CVE-2022-0924 is classified as a medium severity vulnerability due to its potential to cause denial-of-service through an out-of-bounds read in the tiffcp tool.
How do I fix CVE-2022-0924?
To fix CVE-2022-0924, users should update libtiff to versions later than 4.3.0 or apply the specific patch available in commit 408976c4.
Which software versions are affected by CVE-2022-0924?
CVE-2022-0924 affects libtiff version 4.3.0 and may also be relevant to certain older versions of Debian and Fedora distributions.
What risks are associated with CVE-2022-0924?
The risk associated with CVE-2022-0924 includes potential denial-of-service attacks from specially crafted TIFF files.
Is there a workaround for CVE-2022-0924?
Currently, the best workaround for CVE-2022-0924 is to avoid processing untrusted TIFF files until the software is updated.