CVE-2022-2953: Medium severity LibTIFF libtiff vulnerability
An out-of-bound read flaw was found in LibTIFF, in extractImageSection in the tools/tiffcrop.c:6905, allowing attackers to cause a denial of service via a crafted tiff file.
Other sources
LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 48d6ece8.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-2953?
The severity of CVE-2022-2953 is medium with a severity value of 5.5.
How can attackers exploit CVE-2022-2953?
Attackers can exploit CVE-2022-2953 by causing a denial-of-service via a crafted TIFF file.
How can I fix CVE-2022-2953?
If you compile libtiff from sources, the fix is available with commit 48d6ece8.
Which versions of LibTIFF are affected by CVE-2022-2953?
LibTIFF versions 4.2.0-1+deb11u4, 4.5.0-6, and 4.5.1+git230720-1 are affected by CVE-2022-2953.
Where can I find more information about CVE-2022-2953?
You can find more information about CVE-2022-2953 on the following references: [GitLab CVE-2022-2953](https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-2953.json), [GitLab Commit 48d6ece8](https://gitlab.com/libtiff/libtiff/-/commit/48d6ece8389b01129e7d357f0985c8f938ce3da3), [GitLab Issue #414](https://gitlab.com/libtiff/libtiff/-/issues/414).