CVE-2022-3598: Medium severity IBM Cognos Analytics vulnerability
LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit cfbb883b.
Other sources
LibTIFF is vulnerable to a denial of service, caused by an out-of-bounds write flaw in the extractContigSamplesShifted24bits function in tools/tiffcrop.c. By persuading a victim to open a specially-crafted TIFF image file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.1.0+git191117-2~deb10u8Fixed in 4.2.0-1+deb11u4Fixed in 4.2.0-1+deb11u5Fixed in 4.5.0-6+deb12u1Fixed in 4.5.1+git230720-3 - Upgrade
Upgrade
libtiff/libtiffto a version that resolves this vulnerability.Patch cfbb883bf6ea7bedcb04177cc4e52d304522fdff
Event History
Frequently Asked Questions
What is CVE-2022-3598?
CVE-2022-3598 is a vulnerability in LibTIFF 4.4.0 that allows for an out-of-bounds write, leading to a denial-of-service when processing a crafted TIFF file.
How severe is CVE-2022-3598?
CVE-2022-3598 has a severity rating of 6.5 (Medium).
How can I fix CVE-2022-3598?
To fix CVE-2022-3598, users that compile libtiff from sources can apply the fix available with commit cfbb883b.
Which versions of LibTIFF are affected by CVE-2022-3598?
LibTIFF versions up to and including 4.4.0 are affected by CVE-2022-3598.
Are there any references for CVE-2022-3598?
Yes, here are some references for CVE-2022-3598: [link1] [link2] [link3]