CVE-2022-1056: Medium severity tiff vulnerability
Published Mar 28, 2022
·Updated
Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 46dc8fcd.
Affected Software
2 affected components
LibTIFF libtiff=4.3.0
NetApp Active Iq Unified Manager Vmware Vsphere
Remediation
Patch Available
Event History
Mar 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1056?
CVE-2022-1056 has a medium severity rating due to its potential to cause a denial-of-service.
2
How do I fix CVE-2022-1056?
To fix CVE-2022-1056, users must update to a patched version of libtiff that includes the fix available in commit 46dc8fcd.
3
Which versions of libtiff are affected by CVE-2022-1056?
CVE-2022-1056 affects libtiff version 4.3.0.
4
What type of attack does CVE-2022-1056 enable?
CVE-2022-1056 enables attackers to cause a denial-of-service by using a crafted TIFF file.
5
Is CVE-2022-1056 relevant for any specific products?
CVE-2022-1056 is relevant for users of libtiff 4.3.0 and NetApp Active IQ Unified Manager.