ZeroHour

CVE-2022-1622

PoC
CVSS 3.1
5.5 medium
EPSS
2%p76
Published
()
Modified
Description

LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.

Vendors
libtifffedoraprojectnetappapple
Products
libtiff, fedora, ontap select deploy administration utility, iphone os, macos, tvos, watchos
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.