5.5
CVE-2022-2868
- EPSS 0.32%
- Veröffentlicht 17.08.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:01:50
- Erkennungen
libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.243 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
CWE-1284 Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://www.debian.org/security/2023/dsa-5333
https://lists.debian.org/debian-lts-announce/2023/01/msg00018.html
https://bugzilla.redhat.com/show_bug.cgi?id=2118863