First published: Tue Aug 30 2022(Updated: )
There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libtiff Libtiff | =4.4.0-rc1 | |
Debian Debian Linux | =11.0 | |
debian/tiff | <=4.1.0+git191117-2~deb10u4<=4.1.0+git191117-2~deb10u8 | 4.2.0-1+deb11u4 4.2.0-1+deb11u5 4.5.0-6+deb12u1 4.5.1+git230720-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2519 is a vulnerability in libtiff 4.4.0rc1 that allows for a double free or corruption in the rotateImage() function at tiffcrop.c:8839.
CVE-2022-2519 has a severity level of medium with a severity value of 4.
CVE-2022-2519 affects the libtiff package with versions 4.2.0-1+deb11u4, 4.5.0-6, and 4.5.1+git230720-1 on Debian.
To fix CVE-2022-2519, update the libtiff package to versions 4.2.0-1+deb11u4, 4.5.0-6, or 4.5.1+git230720-1 on Debian.
The CWE of CVE-2022-2519 is CWE-415, which refers to an improper destruction of heap memory.