6.1

CVE-2022-1355

Exploit
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libtiff ≫ Libtiff Version < 4.4.0
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.54% 0.426
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 1.8 4.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

https://security.gentoo.org/glsa/202210-10
Third Party Advisory
https://www.debian.org/security/2023/dsa-5333
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/01/msg00018.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20221014-0007/
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2022-1355
Third Party Advisory
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2074415
Third Party Advisory
Exploit
Issue Tracking
https://gitlab.com/libtiff/libtiff/-/issues/400
Patch
Third Party Advisory
Exploit
Issue Tracking
https://gitlab.com/libtiff/libtiff/-/merge_requests/323
Patch
Third Party Advisory
Issue Tracking