CVE-2022-3597: Medium severity IBM Cognos Analytics vulnerability
LibTIFF 4.4.0 has an out-of-bounds write in TIFFmemcpy in libtiff/tifunix.c:346 when called from extractImageSection, tools/tiffcrop.c:6826, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.
Other sources
LibTIFF is vulnerable to a denial of service, caused by an out-of-bounds write flaw in the TIFFmemcpy function in libtiff/tifunix.c. By persuading a victim to open a specially-crafted TIFF image file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.1.0+git191117-2~deb10u8Fixed in 4.2.0-1+deb11u4Fixed in 4.2.0-1+deb11u5Fixed in 4.5.0-6+deb12u1Fixed in 4.5.1+git230720-3 - Upgrade
Upgrade
libtiffto a version that resolves this vulnerability.Patch 236b7191f04c60d09ee836ae13b50f812c841047 - Compensating control
Mitigate denial-of-service risk from crafted TIFF files by preventing untrusted users from providing TIFFs to libtiff-consuming workflows (e.g., block/limit processing of externally supplied TIFFs until libtiff is updated).
Event History
Frequently Asked Questions
What is CVE-2022-3597?
CVE-2022-3597 is a vulnerability in LibTIFF 4.4.0 that allows attackers to cause a denial-of-service via a crafted TIFF file.
What is the severity of CVE-2022-3597?
The severity of CVE-2022-3597 is medium with a CVSS score of 6.5.
How can attackers exploit CVE-2022-3597?
Attackers can exploit CVE-2022-3597 by using a crafted TIFF file to trigger an out-of-bounds write in LibTIFF.
What is the affected software for CVE-2022-3597?
The affected software for CVE-2022-3597 includes LibTIFF 4.4.0 and certain versions of Debian Linux and Apple iPadOS.
How can I fix CVE-2022-3597?
To fix CVE-2022-3597, users that compile libtiff from sources can apply the fix available with commit 236b7191f04c60d09ee836ae13b50f812c841047.