CVE-2022-3626: Medium severity IBM Cognos Analytics vulnerability
LibTIFF 4.4.0 has an out-of-bounds write in TIFFmemset in libtiff/tifunix.c:340 when called from processCropSelections, tools/tiffcrop.c:7619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.
Other sources
LibTIFF is vulnerable to a denial of service, caused by an out-of-bounds write flaw in the TIFFmemset function in libtiff/tifunix.c. By persuading a victim to open a specially-crafted TIFF image file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.1.0+git191117-2~deb10u8Fixed in 4.2.0-1+deb11u4Fixed in 4.2.0-1+deb11u5Fixed in 4.5.0-6+deb12u1Fixed in 4.5.1+git230720-3 - Upgrade
Upgrade
libtiff/libtiffto a version that resolves this vulnerability.Patch 236b7191f04c60d09ee836ae13b50f812c841047
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3626.
What is the severity of CVE-2022-3626?
The severity of CVE-2022-3626 is not specified.
How can an attacker exploit CVE-2022-3626?
An attacker can exploit CVE-2022-3626 by using a crafted tiff file to cause a denial-of-service.
What is the affected software?
The affected software is LibTIFF 4.4.0.
How can I fix CVE-2022-3626?
Users can fix CVE-2022-3626 by compiling libtiff from sources with commit 236b7191f04c60d09ee836ae13b50f812c841047 applied.