REDHAT-BUG-2142734: Buffer Overflow
Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
References: https://gitlab.com/libtiff/libtiff/-/issues/386 https://gitlab.com/libtiff/libtiff/-/commit/bd94a9b383d8755a27b5a1bc27660b8ad10b094c https://gitlab.com/libtiff/libtiff/-/issues/381 https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3570.json
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2142734?
The severity of REDHAT-BUG-2142734 is significant as it allows for heap buffer overflows which could lead to application crashes and potential information disclosure.
How do I fix REDHAT-BUG-2142734?
To fix REDHAT-BUG-2142734, update the libtiff library to the latest patched version that addresses the identified vulnerabilities.
What impact does REDHAT-BUG-2142734 have on my system?
The impact of REDHAT-BUG-2142734 can involve unsafe memory access, application crashes, or even information disclosure if exploited.
Which software is affected by REDHAT-BUG-2142734?
The affected software for REDHAT-BUG-2142734 is the libtiff library, specifically the tiffcrop.c utility in version 4.4.0.
What are the potential exploits related to REDHAT-BUG-2142734?
Potential exploits related to REDHAT-BUG-2142734 include triggering memory access violations through crafted TIFF image files.