CVE-2022-3627: Medium severity IBM Cognos Analytics vulnerability
LibTIFF 4.4.0 has an out-of-bounds write in TIFFmemcpy in libtiff/tifunix.c:346 when called from extractImageSection, tools/tiffcrop.c:6860, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 236b7191.
Other sources
LibTIFF is vulnerable to a denial of service, caused by an out-of-bounds write flaw in the TIFFmemcpy function in libtiff/tifunix.c. By persuading a victim to open a specially-crafted TIFF image file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tiffto a version that resolves this vulnerability.Fixed in 4.1.0+git191117-2~deb10u8Fixed in 4.2.0-1+deb11u4Fixed in 4.2.0-1+deb11u5Fixed in 4.5.0-6+deb12u1Fixed in 4.5.1+git230720-3 - Upgrade
Upgrade
libtiffto a version that resolves this vulnerability.Fixed in 4.4.0 - Upgrade
Upgrade
libtiffto a version that resolves this vulnerability.Patch 236b7191
Event History
Frequently Asked Questions
What is CVE-2022-3627?
CVE-2022-3627 is a vulnerability in LibTIFF 4.4.0 that allows attackers to cause a denial-of-service via a crafted tiff file.
How can the CVE-2022-3627 vulnerability be exploited?
The CVE-2022-3627 vulnerability can be exploited by sending a specially crafted tiff file to the target, which triggers an out-of-bounds write in the _TIFFmemcpy function.
Which versions of LibTIFF are affected by CVE-2022-3627?
Versions 4.1.0+git191117-2~deb10u4, 4.2.0-1+deb11u4, 4.5.0-6, and 4.5.1+git230720-1 are affected by CVE-2022-3627.
How can I fix the CVE-2022-3627 vulnerability?
If you compile libtiff from sources, you can apply the fix with commit 236b7191f04c60d09ee836ae13b50f812c841047.
Where can I find more information about CVE-2022-3627?
You can find more information about CVE-2022-3627 on the Debian security tracker and the libtiff GitLab repository.